8.2

CVSS3.1

CVE-2025-66384 -

app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.

๐Ÿ“… Published: Nov. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.8

CVSS3.1

CVE-2025-66372 -

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

๐Ÿ“… Published: Nov. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.1

CVSS3.1

CVE-2025-66386 -

app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.

๐Ÿ“… Published: Nov. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.9

CVSS3.1

CVE-2025-66382 - libexpat: libexpat: Denial of service via crafted file processing

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

๐Ÿ“… Published: Nov. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 20, 2026, 9:45 p.m.

5

CVSS3.1

CVE-2025-66371 -

Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files from the filesystem and expose their content to a remote host.

๐Ÿ“… Published: Nov. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-51734 -

Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

๐Ÿ“… Published: Nov. 28, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 2, 2025, 8:58 p.m.

5

CVSS3.1

CVE-2025-66370 -

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.

๐Ÿ“… Published: Nov. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS4.0

CVE-2025-3261 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: Nov. 27, 2025, 6:11 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 11:01 a.m.

9.9

CVSS3.1

CVE-2025-12421 - Account Takeover via Code Exchange Endpoint

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email aโ€ฆ

๐Ÿ“… Published: Nov. 27, 2025, 5:47 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

4.3

CVSS3.1

CVE-2025-12559 - Information Disclosure in Common Teams API

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

๐Ÿ“… Published: Nov. 27, 2025, 4:36 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 3:16 p.m.
Total resulsts: 349182
Page 2885 of 34,919
ยซ previous page ยป next page
Filters