5.4

CVSS3.1

CVE-2025-55073 - MS Teams plugin OAuth allows editing arbitrary posts

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL.

πŸ“… Published: Nov. 14, 2025, 8:03 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 9:44 p.m.

6.5

CVSS3.1

CVE-2025-55070 - Lack of MFA enforcement in WebSocket connections

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

πŸ“… Published: Nov. 14, 2025, 8:02 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 5:51 p.m.

3.1

CVSS3.1

CVE-2025-41436 - Unauthorized access to archived channel content via threads interface

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

πŸ“… Published: Nov. 14, 2025, 8 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 5:52 p.m.

4.3

CVSS3.1

CVE-2025-11776 - Guest user can discover archived public channels

Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint

πŸ“… Published: Nov. 14, 2025, 7:58 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 5:52 p.m.

7.2

CVSS3.1

CVE-2025-10686 - Creta Testimonial Showcase < 1.2.4 - Editor+ Local File Inclusion

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

πŸ“… Published: Nov. 14, 2025, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-64444 -

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS com…

πŸ“… Published: Nov. 14, 2025, 5:15 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-13161 - IQ Service International|IQ-Support - Arbitrary File Read

IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

πŸ“… Published: Nov. 14, 2025, 3:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-13160 - IQ Service International|IQ-Support - Exposure of Sensitive Information

IQ-Support developed by IQ Service International has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access specific APIs to obtain sensitive information from the internal network.

πŸ“… Published: Nov. 14, 2025, 3 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-7021 -

Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: Nov. 14, 2025, 2:29 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:24 p.m.

4.3

CVSS3.1

CVE-2025-13107 - chromium-browser: Inappropriate implementation in Compositing

Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Nov. 14, 2025, 2:29 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:18 p.m.
Total resulsts: 349182
Page 3011 of 34,919
Β« previous page Β» next page
Filters