8.8

CVSS3.1

CVE-2025-68434 - opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator…

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter configuration. The CSRF protectio…

📅 Published: Dec. 17, 2025, 10:20 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:20 p.m.

8.1

CVSS3.1

CVE-2025-68147 - opensourcepos has a Cross-site Scripting vulnerability

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS) vulnerability exists in the "Return Policy" configuration field. The application d…

📅 Published: Dec. 17, 2025, 10:16 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:16 p.m.

6.4

CVSS4.0

CVE-2025-68145 - mcp-server-git has missing path validation when using --repository flag

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to…

📅 Published: Dec. 17, 2025, 10:12 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:12 p.m.

6.3

CVSS4.0

CVE-2025-68144 - mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local f…

In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., `--output=/path/to/file` for `git_diff`) would be interpreted as command-line options rather than git r…

📅 Published: Dec. 17, 2025, 10:10 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:10 p.m.

6.5

CVSS4.0

CVE-2025-68143 - mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem loca…

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other to…

📅 Published: Dec. 17, 2025, 10:09 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:09 p.m.

6.8

CVSS3.1

CVE-2025-68129 - Auth0-PHP SDK has Improper Audience Validation

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they …

📅 Published: Dec. 17, 2025, 10:07 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:07 p.m.

6.9

CVSS4.0

CVE-2025-14832 - itsourcecode Online Cake Ordering System updateproduct.php sql injection

A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduct.php?action=edit. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly …

📅 Published: Dec. 17, 2025, 10:02 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:02 p.m.

6.6

CVSS4.0

CVE-2025-68118 - Potential Heap Out-of-Bounds Read in freerdp_certificate_data_hash_ via Unsafe _snprintf Usage

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in FreeRDP’s certificate handling code on Windows platforms. The function `freerdp_certificate_data_hash_ uses` the Microsoft-specific `_snprintf` function to format certificate cache fi…

📅 Published: Dec. 17, 2025, 10:01 p.m. 🔄 Last Modified: Dec. 17, 2025, 10:01 p.m.

9.2

CVSS4.0

CVE-2025-68275 - ChurchCRM vulnerable to Stored XSS - Group name > Person Listing

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a stored cross-site scripting vulnerability on the pages `View Active People`, `View Inactive people`, and `View All People`. Version 6.5.3 fixes the issue.

📅 Published: Dec. 17, 2025, 9:53 p.m. 🔄 Last Modified: Dec. 17, 2025, 9:53 p.m.

6.2

CVSS4.0

CVE-2025-68401 - ChurchCRM has Stored Cross-Site Scripting (XSS) vulnerability that leads to session theft and accou…

ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/JS without sufficient sanitization/encoding. When other users later view this content, attacker-controlled JavaScript executes in their browser (stored XSS). In affected contexts …

📅 Published: Dec. 17, 2025, 9:48 p.m. 🔄 Last Modified: Dec. 17, 2025, 9:48 p.m.
Total resulsts: 323198
Page 28 of 32,320
« previous page » next page
Filters