6.8

CVSS3.1

CVE-2025-6515 - Reuse of session IDs in oatpp-mcp leads to session hijacking and prompt hijacking by remote attackeโ€ฆ

The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographically secure. This allows network attackers with access to the oatpp-mcp server to guess future session IDs and hijack legitimate client MCP sessions, returning malicious responses fโ€ฆ

๐Ÿ“… Published: Oct. 20, 2025, 4:13 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-62429 - ClipBucket v5 executes arbitrary PHP code

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbitrary PHP code execution. In /upload/admin_area/actions/update_launch.php, the "type" parameter from a POST request is embedded into PHP tags and executed. Proper sanitization is โ€ฆ

๐Ÿ“… Published: Oct. 20, 2025, 4:08 p.m. ๐Ÿ”„ Last Modified: Nov. 10, 2025, 7:58 p.m.

9.3

CVSS4.0

CVE-2025-10678 - Admin with default credentials in NetBird VPN

NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not chโ€ฆ

๐Ÿ“… Published: Oct. 20, 2025, 3:41 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-40006 - mm/hugetlb: fix folio is still mapped when deleted

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix folio is still mapped when deleted Migration may be raced with fallocating hole. remove_inode_single_folio will unmap the folio if the folio is still mapped. However, it's called without folio lock. If the foliโ€ฆ

๐Ÿ“… Published: Oct. 20, 2025, 3:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-57738 - Apache Syncope: Remote Code Execution by delegated administrators

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machineryโ€ฆ

๐Ÿ“… Published: Oct. 20, 2025, 2:43 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.5

CVSS3.1

CVE-2025-8884 - IDOR in VHS Electronic Software's ACE Center

Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers.This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255.

๐Ÿ“… Published: Oct. 20, 2025, 2:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-41390 - TruffleHog: specially crafted git repository can lead to arbitrary code execution

An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code execution. An attacker can provide a malicious respository to trigger this vulnerability.

๐Ÿ“… Published: Oct. 20, 2025, 2:15 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-11680 - Out-of-bounds Write in libwebsockets PNG parsing

Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains aโ€ฆ

๐Ÿ“… Published: Oct. 20, 2025, 2:04 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-11679 - Out-of-bounds Read in libwebsockets PNG parsing

Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contaiโ€ฆ

๐Ÿ“… Published: Oct. 20, 2025, 1:58 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS4.0

CVE-2025-11678 - Stack-based Buffer Overflow in libwebsockets DNS response parsing

Stack-based Buffer Overflowย in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label lโ€ฆ

๐Ÿ“… Published: Oct. 20, 2025, 1:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3365 of 34,919
ยซ previous page ยป next page
Filters