2

CVSS4.0

CVE-2025-58747 - Dify MCP OAuth Flow Vulnerable to XSS

Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a victim connects to an attacker-controlled remote MCP server. The vulnerability exists in the OAuth flow implementation where the authorization_url prโ€ฆ

๐Ÿ“… Published: Oct. 17, 2025, 3:48 p.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 7:16 p.m.

7.5

CVSS3.1

CVE-2025-62356 -

A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside of current projects on an end userโ€™s system. The vulnerability can be reached directly and through indirect prompt injection.

๐Ÿ“… Published: Oct. 17, 2025, 3:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11905 - yanyutao0402 ChanCMS gather.js getArticle code injection

A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation results in code injection. The attack may be launched remotely. The exploit has been made public and could be used. Thโ€ฆ

๐Ÿ“… Published: Oct. 17, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:01 a.m.

8.6

CVSS4.0

CVE-2025-26625 - Git LFS may write to arbitrary files via crafted symlinks

Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exโ€ฆ

๐Ÿ“… Published: Oct. 17, 2025, 3:30 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-62353 -

A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end userโ€™s system. The vulnerability can be reached directly and through indirect prompt injection.

๐Ÿ“… Published: Oct. 17, 2025, 3:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-49655 - keras: Keras deserialization of untrusted data

Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded Keras file containing aย TorchModuleWrapper class to run arbitrary code on an end userโ€™s system when loaded despite safe mode being eโ€ฆ

๐Ÿ“… Published: Oct. 17, 2025, 3:20 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11904 - yanyutao0402 ChanCMS hasUse sql injection

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The venโ€ฆ

๐Ÿ“… Published: Oct. 17, 2025, 3:02 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:01 a.m.

8.8

CVSS4.0

CVE-2025-55085 - Web http client: Unchecked Server-Side Malicious Packet Issue

In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior.

๐Ÿ“… Published: Oct. 17, 2025, 2:22 p.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 2:33 p.m.

6.5

CVSS3.1

CVE-2025-48087 - WordPress Memberlite Shortcodes plugin <= 1.4.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1.

๐Ÿ“… Published: Oct. 17, 2025, 2:18 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:12 p.m.

5.3

CVSS4.0

CVE-2025-11903 - yanyutao0402 ChanCMS update sql injection

A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a manipulation of the argument cid can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The โ€ฆ

๐Ÿ“… Published: Oct. 17, 2025, 2:02 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.
Total resulsts: 349182
Page 3379 of 34,919
ยซ previous page ยป next page
Filters