9.6

CVSS3.1

CVE-2025-64709 - Typebot May Expose AWS EKS Credentials via Server Side Request Forgery in Webhook Block

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) functionality allows authenticated users to make arbitrary HTTP requests from the server, including access to AWS Instance…

πŸ“… Published: Nov. 13, 2025, 7:42 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 2:23 p.m.

7.8

CVSS3.1

CVE-2025-46369 -

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

πŸ“… Published: Nov. 13, 2025, 7:41 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:56 p.m.

3.3

CVSS3.1

CVE-2025-46370 -

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.

πŸ“… Published: Nov. 13, 2025, 7:38 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:26 p.m.

8.7

CVSS4.0

CVE-2022-4984 - ZenTao Biz < 6.5, Max < 3.0, & Open Source Edition 16.5/16.5beta1 SQL Injection via user-login.html

ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source Edition < 16.5.beta1 contain an SQL injection vulnerability in the login functionality. The application does not properly validate the account parameter on /zentao/user-login.html before using it in a data…

πŸ“… Published: Nov. 13, 2025, 7:37 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2025-46362 -

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering.

πŸ“… Published: Nov. 13, 2025, 7:34 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:28 p.m.

6.6

CVSS3.1

CVE-2025-46368 -

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

πŸ“… Published: Nov. 13, 2025, 7:30 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:27 p.m.

7.8

CVSS3.1

CVE-2025-46367 -

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Action vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Code Execution.

πŸ“… Published: Nov. 13, 2025, 7:23 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

8.8

CVSS3.1

CVE-2025-43515 - Apple Compressor Remote Code Execution via External Connections

The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauthenticated user on the same network as a Compressor server may be able to execute arbitrary code.

πŸ“… Published: Nov. 13, 2025, 7:03 p.m. πŸ”„ Last Modified: April 22, 2026, 9:15 p.m.

5.3

CVSS4.0

CVE-2025-13123 - AMTT Hotel Broadband Operation System get_firstdate.php sql injection

A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdate.php. Executing manipulation of the argument uid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publis…

πŸ“… Published: Nov. 13, 2025, 7:02 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 12:19 p.m.

6.9

CVSS4.0

CVE-2025-13122 - SourceCodester Patients Waiting Area Queue Management System api_patient_checkin.php getPatientAppo…

A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_patient_checkin.php. Performing manipulation of the argument appointmentID results in sql injection. It is possible to in…

πŸ“… Published: Nov. 13, 2025, 6:02 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:30 p.m.
Total resulsts: 349182
Page 3018 of 34,919
Β« previous page Β» next page
Filters