9.8

CVSS3.1

CVE-2025-65896 -

SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

πŸ“… Published: Dec. 2, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6:23 p.m.

3.5

CVSS3.1

CVE-2025-65858 -

A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.

πŸ“… Published: Dec. 2, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:08 p.m.

7.5

CVSS3.1

CVE-2025-65877 -

Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 'title' parameter in com.wanli.lvzhoucms.service.ContentService#findPage. The parameter is concatenated directly into a dynamic SQL query without sanitization or prepared statements…

πŸ“… Published: Dec. 2, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6:20 p.m.

6.1

CVSS3.1

CVE-2025-65186 -

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.

πŸ“… Published: Dec. 2, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 4:48 p.m.

7.5

CVSS3.1

CVE-2025-65844 -

EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint is accessible without authentication by default, and server-side validation of uploaded files is insufficient. This can be abused to upload arbitrary c…

πŸ“… Published: Dec. 2, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 4:15 a.m.

6.1

CVSS3.1

CVE-2025-65881 -

Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php.

πŸ“… Published: Dec. 2, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 6:57 p.m.

6.8

CVSS3.1

CVE-2025-59705 -

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.

πŸ“… Published: Dec. 2, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 7:39 p.m.

7.2

CVSS3.1

CVE-2025-59697 -

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration to start a root shell upon boot of the host OS. This is called F06.

πŸ“… Published: Dec. 2, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 7:31 p.m.

9.8

CVSS3.1

CVE-2025-59695 -

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.

πŸ“… Published: Dec. 2, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 1:35 p.m.

7.1

CVSS3.1

CVE-2025-66448 - vLLM vulnerable to remote code execution via transformers_utils/get_config

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm loads a model config that contains an auto_map entry, the config class resolves that mapping with ge…

πŸ“… Published: Dec. 1, 2025, 10:45 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 5:52 p.m.
Total resulsts: 349182
Page 2861 of 34,919
Β« previous page Β» next page
Filters