5.4

CVSS3.1

CVE-2025-13632 - chromium-browser: Inappropriate implementation in DevTools

Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)

πŸ“… Published: Dec. 2, 2025, 7 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 7:55 p.m.

8.8

CVSS3.1

CVE-2025-13631 -

Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High)

πŸ“… Published: Dec. 2, 2025, 7 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

8.8

CVSS3.1

CVE-2025-13630 - chromium-browser: Type Confusion in V8

Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Dec. 2, 2025, 7 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.5

CVSS3.1

CVE-2025-61729 - Excessive resource consumption when printing error string for host certificate validation in crypto…

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can…

πŸ“… Published: Dec. 2, 2025, 6:54 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:25 p.m.

7.7

CVSS3.1

CVE-2025-66468 - Aimeos GrapesJS CMS extension possible stores XSS exploitable by authenticated editors

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy …

πŸ“… Published: Dec. 2, 2025, 6:40 p.m. πŸ”„ Last Modified: March 10, 2026, 7:38 p.m.

8.5

CVSS4.0

CVE-2025-34352 - JumpCloud Remote Assist < 0.317.0 Arbitrary File Write/Delete via Insecure Temp Directory

JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Windows Agent as NT AUTHORITY\SYSTEM during agent uninstall or update operations. The Remote Assist uninstaller performs privileged create, write, execute, and delete actions on pre…

πŸ“… Published: Dec. 2, 2025, 6:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-66460 - Lookyloo vulnerable to XSS due to lack of escaping in HTML elements passed to Datatables

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, Lookyloo passed improperly escaped values to cells rendered in datatables using the orthogonal-data feature. It is definitely exploitable from the popup …

πŸ“… Published: Dec. 2, 2025, 6:34 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 2:57 p.m.

5.3

CVSS4.0

CVE-2025-66459 - Lookyloo vulnerable to XSS due to unescaped error message passed to innerHTML

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, a XSS vulnerability can be triggered when a user submits a list of URLs to capture, one of them contains a HTML element, and the capture fails. Then, the…

πŸ“… Published: Dec. 2, 2025, 6:32 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 2:58 p.m.

5.3

CVSS4.0

CVE-2025-66458 - Lookyloo has multiple XSS due to unsafe use of f-strings in Markup

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, there are multiple XSS due to unsafe use of f-strings in Markup. The issue requires a malicious 3rd party server responding with a JSON document containi…

πŸ“… Published: Dec. 2, 2025, 6:30 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 2:58 p.m.

6.5

CVSS3.1

CVE-2025-66454 - Arcade MCP Default Hardcoded Worker Secret Allows Full Unauthorized Access to All HTTP MCP Worker E…

Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret ("dev") that is never validated or overridden during normal server startup. As a result, any unauthenticated attacker who knows this default key can f…

πŸ“… Published: Dec. 2, 2025, 6:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2846 of 34,919
Β« previous page Β» next page
Filters