6.3

CVSS4.0

CVE-2025-13877 - nocobase JWT Service jwt-service.ts hard-coded key

A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument API_KEY results in use of hard-coded cryptographic key . Tโ€ฆ

๐Ÿ“… Published: Dec. 2, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-12630 - Upload.am File Hosting VPN < 1.0.1 - Contributor+ Arbitrary Option Disclosure

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

๐Ÿ“… Published: Dec. 2, 2025, 3:57 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-57850 - Codeready-ws: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a nonโ€ฆ

๐Ÿ“… Published: Dec. 2, 2025, 3:49 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-58113 -

An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.7.3.401. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive informaโ€ฆ

๐Ÿ“… Published: Dec. 2, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Dec. 10, 2025, 11:30 p.m.

0.0

CVE-2025-13890 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12494. Reason: This candidate is a reservation duplicate of CVE-2025-12494. Notes: All CVE users should reference CVE-2025-12494 instead of this candidate. All references and descriptions in this candidate have been removed to prevโ€ฆ

๐Ÿ“… Published: Dec. 2, 2025, 3:25 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 3:46 p.m.

7.5

CVSS3.1

CVE-2025-64460 - Potential denial-of-service vulnerability in XML serializer text extraction

An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion via specially crafted โ€ฆ

๐Ÿ“… Published: Dec. 2, 2025, 3:15 p.m. ๐Ÿ”„ Last Modified: Dec. 10, 2025, 9:47 p.m.

4.3

CVSS3.1

CVE-2025-13372 - Potential SQL injection in FilteredRelation column aliases on PostgreSQL

An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet.annotate()` or `QuerySet.alias()` on Postgreโ€ฆ

๐Ÿ“… Published: Dec. 2, 2025, 3:13 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 12:57 p.m.

4.8

CVSS4.0

CVE-2025-13876 - Rareprob HD Video Player All Formats App com.rocks.music.videoplayer path traversal

A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is an unknown function of the component com.rocks.music.videoplayer. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been discloseโ€ฆ

๐Ÿ“… Published: Dec. 2, 2025, 3:02 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 11:30 p.m.

5.3

CVSS4.0

CVE-2025-13875 - Yohann0617 oci-helper OCI Configuration Upload OciServiceImpl.java addCfg path traversal

A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file src/main/java/com/yohann/ocihelper/service/impl/OciServiceImpl.java of the component OCI Configuration Upload. Executing manipulation of the argument File can lead to path traversโ€ฆ

๐Ÿ“… Published: Dec. 2, 2025, 3:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-13505 - Stored XSS in Datateam's Datactive

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Datateam Information Technologies Inc. Datactive allows Stored XSS.This issue affects Datactive: from 2.13.34 bโ€ฆ

๐Ÿ“… Published: Dec. 2, 2025, 2:22 p.m. ๐Ÿ”„ Last Modified: Jan. 30, 2026, 8:32 p.m.
Total resulsts: 349182
Page 2848 of 34,919
ยซ previous page ยป next page
Filters