10

CVSS4.0

CVE-2025-11925 - Incorrect Content-Type Header

Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 17, 2025, 7:56 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 5:14 p.m.

6.3

CVSS3.1

CVE-2025-62511 - yt-grabber-tui local arbitrary file overwrite via TOCTOU race in config file creation

yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition (CWE-367) in the creation of the default configuration file config.json. In version 1.0, load_json_settings in Sett…

πŸ“… Published: Oct. 17, 2025, 7:55 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

5.3

CVSS4.0

CVE-2025-11911 - Shenzhen Ruiming Technology Streamax Crocus DeviceFault.do Query sql injection

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Action=Query. The manipulation of the argument sortField results in sql injection. It is possible to launch the attack remotely. The exploit is now public …

πŸ“… Published: Oct. 17, 2025, 7:32 p.m. πŸ”„ Last Modified: Oct. 31, 2025, 5:11 p.m.

5.3

CVSS4.0

CVE-2025-11910 - Shenzhen Ruiming Technology Streamax Crocus MemoryState.do query sql injection

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the function Query of the file /MemoryState.do?Action=Query. The manipulation of the argument orderField leads to sql injection. It is possible to initiate the attack remotely. The exploit…

πŸ“… Published: Oct. 17, 2025, 7:32 p.m. πŸ”„ Last Modified: Oct. 31, 2025, 5:12 p.m.

6.9

CVSS4.0

CVE-2025-34282 - ThingsBoard < v4.2.1 SVG Image SSRF

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes the SVG file in a way that parses external references, it may in…

πŸ“… Published: Oct. 17, 2025, 6:33 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 1:27 a.m.

6.2

CVSS4.0

CVE-2025-34281 - Stored Cross-Site Scripting (XSS) in ThingsBoard

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if t…

πŸ“… Published: Oct. 17, 2025, 6:33 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 4:16 p.m.

5.3

CVSS4.0

CVE-2025-11909 - Shenzhen Ruiming Technology Streamax Crocus RepairRecord.do queryLast sql injection

A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /RepairRecord.do?Action=QueryLast. Executing manipulation of the argument orderField can lead to sql injection. The attack may be performed from remote. T…

πŸ“… Published: Oct. 17, 2025, 6:32 p.m. πŸ”„ Last Modified: Oct. 31, 2025, 5:18 p.m.

5.3

CVSS4.0

CVE-2025-11908 - Shenzhen Ruiming Technology Streamax Crocus FileDir.do uploadFile unrestricted upload

A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Performing manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out rem…

πŸ“… Published: Oct. 17, 2025, 6:32 p.m. πŸ”„ Last Modified: Oct. 31, 2025, 5:19 p.m.

3

CVSS3.1

CVE-2025-62505 - SSRF in lobehub/lobe-chat with native web fetch module

LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. A client can supply an arbitrary urls array together with impls containing the value naive. The service p…

πŸ“… Published: Oct. 17, 2025, 6:18 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

5.4

CVSS3.1

CVE-2025-62430 - ClipBucket v5 stored XSS via video/photo fields

ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site scripting (XSS) in multiple video and photo metadata fields. For videos the Tags field and the Genre, Actors, Producer, Executive Producer, and Director fields in Movieinfos accep…

πŸ“… Published: Oct. 17, 2025, 5:50 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 7:58 p.m.
Total resulsts: 343984
Page 2859 of 34,399
Β« previous page Β» next page
Filters