9.8

CVSS3.1

CVE-2025-13615 - StreamTube Core <= 4.78 - Unauthenticated Arbitrary User Password Change

The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthe…

πŸ“… Published: Nov. 30, 2025, 1:53 a.m. πŸ”„ Last Modified: April 21, 2026, 6 p.m.

6.5

CVSS3.1

CVE-2025-66424 -

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

πŸ“… Published: Nov. 30, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 4:50 p.m.

4.2

CVSS3.1

CVE-2025-66433 -

HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed in 24.12.14, 25.0.3, and 25.3.1. The earliest affected version is 24.7.3.

πŸ“… Published: Nov. 30, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-66422 -

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

πŸ“… Published: Nov. 30, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:11 p.m.

7.1

CVSS3.1

CVE-2025-66423 -

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

πŸ“… Published: Nov. 30, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:10 p.m.

5.4

CVSS3.1

CVE-2025-66420 -

Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and 6.0.67.

πŸ“… Published: Nov. 30, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2025-66432 -

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

πŸ“… Published: Nov. 30, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-66421 -

Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.69.

πŸ“… Published: Nov. 30, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

1

CVSS4.0

CVE-2025-6666 - motogadget mo.lock Ignition Lock NFC hard-coded key

A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing manipulation can lead to use of hard-coded cryptographic key . The physical device can be targeted for the attack. A…

πŸ“… Published: Nov. 29, 2025, 9:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-66291 - OrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Interview Attachm…

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files based solely on an authenticated session and user-supplied identifiers, without verifying whether the requester has permis…

πŸ“… Published: Nov. 29, 2025, 3:08 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:30 p.m.
Total resulsts: 349182
Page 2878 of 34,919
Β« previous page Β» next page
Filters