9.8

CVSS3.1

CVE-2025-55469 -

Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 5, 2025, 2:38 p.m.

9.1

CVSS3.1

CVE-2025-65669 -

An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 3, 2025, 8:50 p.m.

9.8

CVSS3.1

CVE-2025-65236 -

OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 8:47 p.m.

7.5

CVSS3.1

CVE-2025-46174 -

Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 4, 2025, 7:16 p.m.

8.8

CVSS3.1

CVE-2025-45311 -

Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary operations as root. NOTE: this is disputed by multiple parties because the action for a triggered rule can legitimately be an arbitrary operation as root. Thus, the software is behavinโ€ฆ

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-65239 -

Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs.

๐Ÿ“… Published: Nov. 26, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 30, 2025, 3:57 p.m.

5.4

CVSS3.1

CVE-2025-65963 - CFiles Unauthorized Folder/ZIP Access in Public Spaces

Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new folders, up- and download files as a ZIP archive in public spaces. Private spaces are not affected. This issue has been โ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 11:38 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS4.0

CVE-2025-66019 - pypdf manipulated LZWDecode streams can exhaust RAM

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patchedโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 11:38 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-65957 - Core Bot is Leaking Sensitive Credentials in Logs, Errors, and Messages

Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_API_KEY, TOKEN) are loaded using environment variables, but there are cases in code (error handling, summaries, webhooks) where configuration summaries may inadvertently leak sensโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 11:33 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-65956 - Formwork CMS Has a Stored Cross-Site Scripting (XSS) Vulnerability in Blog Tags

Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored crossโ€‘site scripting (XSS). Any user with credentials to the Formwork CMS who accesses or edits an affected blog post will have attackerโ€‘controโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 11:20 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 8:30 p.m.
Total resulsts: 349182
Page 2901 of 34,919
ยซ previous page ยป next page
Filters