3.3

CVSS3.1

CVE-2025-64524 - CUPS rastertopclx Filter Vulnerable to Heap Buffer Overflow Leading to Potential Arbitrary Code Exe…

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and prior, a heap-buffer-overflow vulnerability in the rastertopclx filter causes the program to crash with a segmentation fault whe…

📅 Published: Nov. 20, 2025, 6:05 p.m. 🔄 Last Modified: Dec. 15, 2025, 2:35 p.m.

8.9

CVSS4.0

CVE-2025-64428 - DataEase DB2 JNDI Vulnerability

Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbaname, and iiopname schemes. The vulnerability has been fixed i…

📅 Published: Nov. 20, 2025, 5:07 p.m. 🔄 Last Modified: Nov. 24, 2025, 2:21 p.m.

6.9

CVSS4.0

CVE-2025-64185 - Open OnDemand RPM packages create world writable locations

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.

📅 Published: Nov. 20, 2025, 4:58 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-62724 - Open OnDemand allowlist bypass using symlinks in directory downloads (TOCTOU)

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) attack when downloading zip files to access files outside of the OOD_ALLOWLIST. This vulnerability impacts sites that use the file browser allowlists in all curr…

📅 Published: Nov. 20, 2025, 4:53 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-62709 - ClipBucket v5 is vulnerable to password reset link manipulation

ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build the server URL from the incoming HTTP Host header when the configuration base_url is not set. Because Host is a client-controlled header, an…

📅 Published: Nov. 20, 2025, 4:50 p.m. 🔄 Last Modified: Nov. 25, 2025, 7:04 p.m.

7.3

CVSS3.1

CVE-2025-12121 - CVE-2025-12121

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open…

📅 Published: Nov. 20, 2025, 4:39 p.m. 🔄 Last Modified: Dec. 10, 2025, 5:45 p.m.

7.3

CVSS3.1

CVE-2025-12120 - CVE-2025-12120

Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.lua file is intended for project-specific configuration but can contain executable Lua logic. This behavior could allow …

📅 Published: Nov. 20, 2025, 4:38 p.m. 🔄 Last Modified: Dec. 10, 2025, 5:47 p.m.

5.6

CVSS4.0

CVE-2025-13437 - Arbitrary node_modules Directory Deletion in Google zx

When zx is invoked with --prefer-local=<path>, the CLI creates a symlink named ./node_modules pointing to <path>/node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes …

📅 Published: Nov. 20, 2025, 4:25 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-62875 - Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock

An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.

📅 Published: Nov. 20, 2025, 4:02 p.m. 🔄 Last Modified: Jan. 15, 2026, 7:03 p.m.

5.1

CVSS4.0

CVE-2025-62731 - Stored XSS in SOPlanning

SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. By default only administrators and users with special privileges a…

📅 Published: Nov. 20, 2025, 3:44 p.m. 🔄 Last Modified: Nov. 24, 2025, 1:53 p.m.
Total resulsts: 349182
Page 2949 of 34,919
« previous page » next page
Filters