7.5

CVSS3.1

CVE-2025-61234 -

Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local network without authentication. This allows an attacker to interact with the device via a TCP socket without credentials. Additionally, sending an HTTP request to the service on port 88โ€ฆ

๐Ÿ“… Published: Oct. 29, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-60542 - TypeORM: SQL Injection via crafted request to repository.save or repository.update

SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.

๐Ÿ“… Published: Oct. 29, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-45161 -

A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via a URL, an image load, an XMLHttpRequest, etc. and can result in exposure of data or unintended code execution.

๐Ÿ“… Published: Oct. 29, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.6

CVSS3.1

CVE-2025-4665 -

WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades into insecure deserialization (PHP Object Injection). The weakness arises due to insufficient validation of user input in plugin endpoints, allowing โ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 11:54 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-64095 - DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files โ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:46 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 7:39 p.m.

6.4

CVSS3.1

CVE-2025-64094 - DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix for CVE-2025-48378. Tโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:44 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 7:38 p.m.

4.3

CVSS3.1

CVE-2025-62802 - DNN CKEditor Provider allows unauthenticated upload out-of-the-box

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most imโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:42 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 7:38 p.m.

5.4

CVSS4.0

CVE-2025-62801 - FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixeโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:36 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 1:24 p.m.

5.3

CVSS4.0

CVE-2025-62800 - FastMCP vulnerable to reflected XSS in client's callback page

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oauth_callback.py) where unescaped user-controlled values are inserted into the generated HTML, allowing arbitrary JavaScrโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:34 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 1:49 a.m.

5.4

CVSS3.1

CVE-2025-62798 - Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax

Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }} were evaluated by Vuโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 8:58 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3234 of 34,919
ยซ previous page ยป next page
Filters