6.5

CVSS3.1

CVE-2025-65113 - ClipBucket v5 Unauthenticated Object Flagging Vulnerability

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerability in the AJAX flagging system allows any unauthenticated user to flag any content (users, videos, photos, collections) on the platform. This can lead to mass flagging attacks, …

πŸ“… Published: Nov. 29, 2025, 12:34 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 9:51 p.m.

4

CVSS3.1

CVE-2025-64715 - Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference AWS security group IDs that do not exist or are not attached to any network in…

πŸ“… Published: Nov. 29, 2025, 12:11 a.m. πŸ”„ Last Modified: Dec. 4, 2025, 8:38 p.m.

6.1

CVSS3.1

CVE-2025-65892 -

Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted URL to the passQueryParameters function with the xml parameter enabled.

πŸ“… Published: Nov. 29, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 4:03 p.m.

6.1

CVSS3.1

CVE-2025-65540 -

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are directly rendered into HTML without proper sanitization or encoding, allowing attackers to inject and execute malicious scri…

πŸ“… Published: Nov. 29, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 4:05 p.m.

6.5

CVSS3.1

CVE-2025-13683 -

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

πŸ“… Published: Nov. 28, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 9:18 p.m.

8.8

CVSS4.0

CVE-2025-12183 - org.lz4:lz4-java - Out-of-Bounds Memory Access

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

πŸ“… Published: Nov. 28, 2025, 3:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-11156 - Improper Service Loading Vulnerability in Netskope Endpoint DLP Driver

Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited,Β a local, authenticated user with Administrator privilegesΒ can improperly load the driver as a generic kernel service. This triggers the flaw, causing a system crash (Blue…

πŸ“… Published: Nov. 28, 2025, 2:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-59792 - Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

πŸ“… Published: Nov. 28, 2025, 2:21 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 5:04 p.m.

5.4

CVSS3.1

CVE-2025-59790 - Apache Kvrocks: RESET command grants admin privileges

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

πŸ“… Published: Nov. 28, 2025, 2:20 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 5:03 p.m.

8

CVSS3.0

CVE-2025-12638 - Path Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file…

Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extracting tar archives. The vulnerability arises because the function uses Python's tarfile.extractall() method without the security-critical filter='data' parameter. Although Keras attem…

πŸ“… Published: Nov. 28, 2025, 2:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2881 of 34,919
Β« previous page Β» next page
Filters