4.6

CVSS4.0

CVE-2025-64187 - OctoPrint is vulnerable to XSS through Action Command Notifications and Prompts

OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Action Command notifications and prompts popups generated by the printer. An attacker who successfully conviโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 3:11 a.m. ๐Ÿ”„ Last Modified: Dec. 4, 2025, 9:37 p.m.

8.8

CVSS3.1

CVE-2025-64184 - Dosage vulnerable to Directory Traversal through crafted HTTP responses

Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing charactโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-64180 - Manager-io/Manager: Complete Bypass of SSRF Protection via Time-of-Check Time-of-Use (TOCTOU)

Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network resources. The flaw lies in the fundamental design of the DNS validation mechanism. A Time-of-Check Time-of-Use (TOCTOU)โ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 2:58 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-11546 -

CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends speciaโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 1:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-48985 -

A vulnerability in Vercelโ€™s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade. More details: https://vercel.com/changelog/cve-2025-48985-input-validatioโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 12:43 a.m. ๐Ÿ”„ Last Modified: Feb. 4, 2026, 9:11 p.m.

6.9

CVSS3.1

CVE-2025-52662 -

A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade. More details: https://vercel.com/changelog/cve-2025-52662-xss-on-nuxt-devtools

๐Ÿ“… Published: Nov. 7, 2025, 12:43 a.m. ๐Ÿ”„ Last Modified: Feb. 4, 2026, 9:01 p.m.

6.5

CVSS3.1

CVE-2025-63784 -

An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerability occurs because the application trusts the X-Forwarded-Host header value without proper validation when constructing aโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 4:07 p.m.

9.1

CVSS3.1

CVE-2025-63690 -

In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is possible to execute any Java class with a parameterless constructor and its methods with parameter type String through reflection. At this time, the โ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 4:10 p.m.

5.5

CVSS3.1

CVE-2025-12748 - Libvirt: denial of service in xml parsing

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too mโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-63717 -

The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie restrictions, allowing attackeโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 17, 2025, 6:40 p.m.
Total resulsts: 349182
Page 3111 of 34,919
ยซ previous page ยป next page
Filters