5

CVSS3.1

CVE-2025-64706 - Typebot IDOR Vulnerability: Unauthorized API Token Deletion and Exposure

Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API token management endpoint. An authenticated attacker can delete any user's API token and retrieve its value by simply knowing th…

πŸ“… Published: Nov. 13, 2025, 5:49 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 2:14 p.m.

6.9

CVSS4.0

CVE-2025-12785 - Certain HP LaserJet Pro Printers – Potential Information Disclosure

Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server.

πŸ“… Published: Nov. 13, 2025, 5:38 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 4:34 p.m.

6.9

CVSS4.0

CVE-2025-12784 - Certain HP LaserJet Pro Printers – Potential Information Disclosure

Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server.

πŸ“… Published: Nov. 13, 2025, 5:35 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 4:38 p.m.

6.1

CVSS3.1

CVE-2025-59480 - Inadequate validation of SSO redirect credentials permits credential theft

Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses

πŸ“… Published: Nov. 13, 2025, 5:32 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 7:37 p.m.

3.1

CVSS3.1

CVE-2025-11777 - Cross-team channel membership access

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint

πŸ“… Published: Nov. 13, 2025, 5:32 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 6:05 p.m.

6.9

CVSS4.0

CVE-2025-13121 - cameasy Liketea API Endpoint StoreController.php list sql injection

A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/app/Http/Controllers/Front/StoreController.php of the component API Endpoint. Such manipulation of the argument lng/lat leads to sql injection. The attack may be performed from rem…

πŸ“… Published: Nov. 13, 2025, 4:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-20346 - Cisco Catalyst Center Privilege Escalation Vulnerability

A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should require Administrator privileges. The attacker would need valid read-only user credentials. This vulnerability is due to improper role-based access control (RBAC). An attacker…

πŸ“… Published: Nov. 13, 2025, 4:27 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

4.7

CVSS3.1

CVE-2025-20355 - Cisco Catalyst Center Software HTTP Open Redirect Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploi…

πŸ“… Published: Nov. 13, 2025, 4:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-20353 - Cisco Catalyst Center Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input.…

πŸ“… Published: Nov. 13, 2025, 4:18 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 4:56 p.m.

6.3

CVSS3.1

CVE-2025-20349 - Cisco DNA Center API Command Injection Vulnerability

A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted container as the root user. This vulnerability is due to insufficient validation of user-supplied input in REST API request parameters. An attacker…

πŸ“… Published: Nov. 13, 2025, 4:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.
Total resulsts: 349182
Page 3019 of 34,919
Β« previous page Β» next page
Filters