6.9

CVSS4.0

CVE-2025-66028 - OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation

OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying thi…

πŸ“… Published: Nov. 26, 2025, 6:11 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 1:57 p.m.

8.8

CVSS4.0

CVE-2025-65966 - OneUptime Unauthorized User Creation via API

OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in version 9.1.0.

πŸ“… Published: Nov. 26, 2025, 6:10 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 2:05 p.m.

2.7

CVSS3.1

CVE-2025-20373 - Sensitive Information Disclosure in β€œ_internalβ€œ index through Splunk Add-On for Palo Alto Networks

In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition of new β€œData Security Accountsβ€œ. The vulnerability would require either local access to the log files or administrative access to internal indexes…

πŸ“… Published: Nov. 26, 2025, 5:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-64130 - Zenitel TCIV-3+ Cross-site Scripting

Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.

πŸ“… Published: Nov. 26, 2025, 5:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-64129 - Zenitel TCIV-3+ Out-of-bounds Write

Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the device.

πŸ“… Published: Nov. 26, 2025, 5:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2021-4472 - Python-mistralclient: mistral-dashboard: local file inclusion through the 'create workbook' feature

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.

πŸ“… Published: Nov. 26, 2025, 5:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-64128 - Zenitel TCIV-3+ OS Command Injection

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to append arbitrary data. This could allow an unauthenticated attacker to inject arbitrary commands.

πŸ“… Published: Nov. 26, 2025, 5:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-64127 - Zenitel TCIV-3+ OS Command Injection

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute arbitrary commands remotely.

πŸ“… Published: Nov. 26, 2025, 5:50 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-64126 - Zenitel TCIV-3+ OS Command Injection

An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without verifying it is a valid IP address or filtering potentially malicious characters. This could allow an unauthenticated attacker to inject arbitrary …

πŸ“… Published: Nov. 26, 2025, 5:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-11461 - Frappe CRM 1.53.1 β€” Multiple SQL Injections in Dashboard Controller

Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.

πŸ“… Published: Nov. 26, 2025, 5:45 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 4:32 p.m.
Total resulsts: 349182
Page 2894 of 34,919
Β« previous page Β» next page
Filters