9.8

CVSS3.1

CVE-2025-65276 -

An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru commit 5919decaff2681dc250e934814fc3a35f6093ee5 (2021-07-02). Due to missing authentication checks on /admin_index.php, an attacker can directly access th…

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 3:34 p.m.

6.7

CVSS3.1

CVE-2025-59820 - Krita: Krita: Heap-based buffer overflow via manipulated TGA file

In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kis_tga_import.cpp (aka KisTgaImport). Control flow proceeds even when a number of pixels becomes negative.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-56396 -

An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 8:16 p.m.

7.5

CVSS3.1

CVE-2025-55471 -

Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 2:37 p.m.

9.8

CVSS3.1

CVE-2025-50399 -

FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:47 p.m.

9.8

CVSS3.1

CVE-2025-26155 -

NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 3:41 p.m.

9.8

CVSS3.1

CVE-2025-50402 -

FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:46 p.m.

7.5

CVSS3.1

CVE-2025-65672 -

Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 2:30 p.m.

7.5

CVSS3.1

CVE-2025-46175 -

Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

6.5

CVSS3.1

CVE-2025-65238 -

Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user records and access sensitive information.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 8:46 p.m.
Total resulsts: 349182
Page 2899 of 34,919
Β« previous page Β» next page
Filters