9.1

CVSS3.1

CVE-2025-61922 - PrestaShop Checkout allows customer account takeover via email

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versi…

πŸ“… Published: Oct. 16, 2025, 5:26 p.m. πŸ”„ Last Modified: Dec. 29, 2025, 8:06 p.m.

4

CVSS4.0

CVE-2025-61909 - Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user

Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 process from a PID file writable by the daemon user…

πŸ“… Published: Oct. 16, 2025, 5:20 p.m. πŸ”„ Last Modified: Oct. 29, 2025, 8:03 p.m.

8.9

CVSS4.0

CVE-2025-62586 - OPEXUS FOIAXpress unauthenticated administrator password reset

OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.

πŸ“… Published: Oct. 16, 2025, 5:20 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.1

CVSS4.0

CVE-2025-61908 - Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference

Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API user with access to an API endpoint that allows specifying a f…

πŸ“… Published: Oct. 16, 2025, 5:16 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 2:57 p.m.

7.1

CVSS4.0

CVE-2025-61907 - Icinga 2 API users could access restricted values in filter expressions

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that …

πŸ“… Published: Oct. 16, 2025, 5:11 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 3:04 p.m.

5.3

CVSS3.1

CVE-2025-61789 - Icinga DB Web hidden/protected custom variables are prone to filter enumeration

Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigne…

πŸ“… Published: Oct. 16, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 6:24 p.m.

7.5

CVSS3.1

CVE-2025-36128 - IBM MQ denial of service

IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.

πŸ“… Published: Oct. 16, 2025, 4:49 p.m. πŸ”„ Last Modified: Oct. 28, 2025, 4:53 p.m.

6.5

CVSS3.1

CVE-2025-58051 - Nextcloud Tables app allowed to include local file via PhpSpreadsheet when importing a table

Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked …

πŸ“… Published: Oct. 16, 2025, 4:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-53092 - Strapi core vulnerable to sensitive data exposure via CORS misconfiguration

Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, Strapi reflects the value of the Origin header back in the Access-Control-Allow-Origin response header without proper vali…

πŸ“… Published: Oct. 16, 2025, 4:29 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 6:44 p.m.

6.3

CVSS4.0

CVE-2025-25298 - Missing Maximum Password Length Validation in Strapi Password Hashing

Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs ignores any bytes beyond 72, so passwords longer than 72 bytes are silently truncated. A user can create an account wit…

πŸ“… Published: Oct. 16, 2025, 4:21 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 1:06 a.m.
Total resulsts: 349182
Page 3389 of 34,919
Β« previous page Β» next page
Filters