7.1

CVSS3.1

CVE-2025-53896 - Kiteworks MFT is vulnerable to Insufficient Session Expiration

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue has been patched in version 9.1.0.

πŸ“… Published: Nov. 29, 2025, 2:24 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 3:11 p.m.

5.1

CVSS3.1

CVE-2025-58436 - OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue h…

πŸ“… Published: Nov. 29, 2025, 2:15 a.m. πŸ”„ Last Modified: Dec. 4, 2025, 5:24 p.m.

9.3

CVSS4.0

CVE-2025-66216 - AIS-catcher has a Buffer Overflow vulnerability in `AIS::Message` leading to DoS/RCE

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message class of AIS-catcher. This vulnerability allows an attacker to write approximately 1KB of arbitrary data into a 128-byte buffer. This issue has been patc…

πŸ“… Published: Nov. 29, 2025, 1:57 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 4:13 p.m.

8.8

CVSS4.0

CVE-2025-66217 - AIS-catcher Integer Underflow in MQTT Packet Parsing leading to Heap Buffer Overflow

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vulnerability allows an attacker to trigger a massive Heap Buffer Overflow by sending a malformed MQTT packet with a manipulated Topic Length…

πŸ“… Published: Nov. 29, 2025, 1:57 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 4:10 p.m.

6.9

CVSS4.0

CVE-2025-66219 - willitmerge has a command Injection vulnerability

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which it concatenates user…

πŸ“… Published: Nov. 29, 2025, 1:34 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 3:52 p.m.

8.6

CVSS4.0

CVE-2025-66201 - LibreChat is Vulnerable to Server-Side Request Forgery (SSRF) in Actions Capability

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by passing specially crafted OpenAPI specs to its "Actions" feature and making the LLM use those actions. It could be used by an authenticated user with …

πŸ“… Published: Nov. 29, 2025, 1:26 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 9:49 p.m.

6.1

CVSS3.1

CVE-2025-66036 - Retro is vulnerable to XSS vulnerability in input handling component

Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cross-site scripting (XSS) in the input handling component. This issue has been patched in version 2.4.7.

πŸ“… Published: Nov. 29, 2025, 1:14 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-66034 - fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script has an arbitrary file write vulnerability that leads to remote code execution when a malicious .designspace file is processed. The…

πŸ“… Published: Nov. 29, 2025, 1:07 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 9:50 p.m.

7.1

CVSS4.0

CVE-2025-66027 - Rallly Information Disclosure Vulnerability in Participant API Leaks Names and Emails Despite Pro P…

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, even when Pro privacy features are enabled. …

πŸ“… Published: Nov. 29, 2025, 12:43 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 8:25 p.m.

9.4

CVSS3.1

CVE-2025-65112 - PubNet Critical Authentication Bypass Allows Unauthenticated Package Upload and Identity Spoofing

PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain atta…

πŸ“… Published: Nov. 29, 2025, 12:38 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 9:51 p.m.
Total resulsts: 349182
Page 2880 of 34,919
Β« previous page Β» next page
Filters