8.7

CVSS4.0

CVE-2025-62614 - BookLore Media API Authentication Bypass

BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an authentication bypass vulnerability in the BookMediaController allows any unauthenticated user to access and download book covers, thumbnails, and complete PDF/CBX page content w…

πŸ“… Published: Oct. 22, 2025, 8:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-62613 - VDO.Ninja Reflected XSS Vulnerability in control.html

VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to before 28.4, a reflected Cross-Site Scripting (XSS) vulnerability exists on examples/control.html through the room parameter, which is improperly sanitized before being rendered in…

πŸ“… Published: Oct. 22, 2025, 8:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-62612 - FastGPT File Reading Node SSRF Vulnerability

FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posing a risk of SSRF attacks. This issue has been patched in version 4.11.1.

πŸ“… Published: Oct. 22, 2025, 8:45 p.m. πŸ”„ Last Modified: Dec. 29, 2025, 7:08 p.m.

8.2

CVSS4.0

CVE-2025-62611 - aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server

aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the client using a rogue server. It is possible to create a rogue MySQL ser…

πŸ“… Published: Oct. 22, 2025, 7:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2025-62247 -

Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allo…

πŸ“… Published: Oct. 22, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 6:13 p.m.

8.1

CVSS3.1

CVE-2025-62610 - Hono Improperly Authorizes JWT Audience Validation

Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an API may accept a valid …

πŸ“… Published: Oct. 22, 2025, 7:24 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 3:56 p.m.

5.7

CVSS4.0

CVE-2025-62513 - OpenBao leaks HTTPRawBody in Audit Logs

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using the ACME functionality of PKI, resulting in short…

πŸ“… Published: Oct. 22, 2025, 7:18 p.m. πŸ”„ Last Modified: Oct. 27, 2025, 8:31 p.m.

4.8

CVSS4.0

CVE-2025-62248 -

A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through …

πŸ“… Published: Oct. 22, 2025, 7:07 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 6:13 p.m.

5.4

CVSS3.1

CVE-2025-24934 - SO_REUSEPORT_LB breaks connect(2) for UDP sockets

Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. However, due to its membership in a load-balancing group, that socket will receive packets originating from any host. This breaks the contract of the connect(2) and implied conne…

πŸ“… Published: Oct. 22, 2025, 5:43 p.m. πŸ”„ Last Modified: April 24, 2026, 12:16 a.m.

9

CVSS4.0

CVE-2025-11957 -

Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.

πŸ“… Published: Oct. 22, 2025, 5:09 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 6:15 p.m.
Total resulsts: 349182
Page 3309 of 34,919
Β« previous page Β» next page
Filters