7.1

CVSS3.1

CVE-2025-63589 -

A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are not sanitized or encoded before being inserted into the generated HTML (navigation links, breadcrumbs, search form action, footer links). An attacker-controlled string placed in the…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:29 p.m.

7.5

CVSS3.1

CVE-2025-63551 -

A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management System (CMS) thru 8.1. This flaw stems from a defect in the XML parsing logic, which allows an attacker to construct a malicious XML entity that forces…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2026, 9:14 p.m.

7.3

CVSS3.1

CVE-2025-60541 -

A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer v1.3.0 to v1.4.2 allows attackers to scan internal resources via a crafted request.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 6:37 p.m.

9.8

CVSS3.1

CVE-2025-27918 -

An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of …

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 5:16 p.m.

7.4

CVSS3.1

CVE-2025-12790 - Rubygem-mqtt: rubygem-mqtt hostname validation

A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-27917 -

An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allo…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 5:16 p.m.

7.5

CVSS3.1

CVE-2025-63560 -

An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2026, 9:16 p.m.

6.1

CVSS3.1

CVE-2025-12789 - Rhsso: open redirect

A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter associated with the openid-connect logout protocol does not properly validate the provided URL.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-63307 -

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 4:14 p.m.

8.2

CVSS3.1

CVE-2025-27919 -

An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later conne…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.
Total resulsts: 349182
Page 3137 of 34,919
Β« previous page Β» next page
Filters