6.8
CVE-2025-6515 - Reuse of session IDs in oatpp-mcp leads to session hijacking and prompt hijacking by remote attackeโฆ
The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographically secure. This allows network attackers with access to the oatpp-mcp server to guess future session IDs and hijack legitimate client MCP sessions, returning malicious responses fโฆ
7.2
CVE-2025-62429 - ClipBucket v5 executes arbitrary PHP code
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbitrary PHP code execution. In /upload/admin_area/actions/update_launch.php, the "type" parameter from a POST request is embedded into PHP tags and executed. Proper sanitization is โฆ
9.3
CVE-2025-10678 - Admin with default credentials in NetBird VPN
NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not chโฆ
0.0
CVE-2025-40006 - mm/hugetlb: fix folio is still mapped when deleted
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix folio is still mapped when deleted Migration may be raced with fallocating hole. remove_inode_single_folio will unmap the folio if the folio is still mapped. However, it's called without folio lock. If the foliโฆ
7.2
CVE-2025-57738 - Apache Syncope: Remote Code Execution by delegated administrators
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machineryโฆ
5.5
CVE-2025-8884 - IDOR in VHS Electronic Software's ACE Center
Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers.This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255.
7.8
CVE-2025-41390 - TruffleHog: specially crafted git repository can lead to arbitrary code execution
An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code execution. An attacker can provide a malicious respository to trigger this vulnerability.
5.9
CVE-2025-11680 - Out-of-bounds Write in libwebsockets PNG parsing
Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains aโฆ
5.9
CVE-2025-11679 - Out-of-bounds Read in libwebsockets PNG parsing
Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contaiโฆ
7.5
CVE-2025-11678 - Stack-based Buffer Overflow in libwebsockets DNS response parsing
Stack-based Buffer Overflowย in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label lโฆ