3.5

CVSS3.1

CVE-2025-62174 - Mastodon allows continued access after password reset via CLI

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts modify --reset-password`, active sessions and access tokens fo…

πŸ“… Published: Oct. 13, 2025, 8:54 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 1:10 p.m.

8.6

CVSS3.1

CVE-2025-61688 - Omni leaks information via the API

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensitive information via an API.

πŸ“… Published: Oct. 13, 2025, 8:46 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 9:30 p.m.

5.3

CVSS3.1

CVE-2025-59836 - Omni is Vulnerable to DoS via Empty Create/Update Resource Requests

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in the Omni Resource Service allows unauthenticated users to cause a server panic and denial of service by sending empty create/update resource requests…

πŸ“… Published: Oct. 13, 2025, 8:43 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 9:33 p.m.

5.3

CVSS4.0

CVE-2025-62252 -

Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in o…

πŸ“… Published: Oct. 13, 2025, 8:42 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:35 p.m.

6.2

CVSS3.1

CVE-2025-62364 - text-generation-webui allows arbitrary file read via symbolic link upload

text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerability exists in the character picture upload feature. An attacker can upload a text file containing a symbolic link to an arbitrary file path. When the a…

πŸ“… Published: Oct. 13, 2025, 8:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-62246 -

Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions allow remote authenticated users t…

πŸ“… Published: Oct. 13, 2025, 8:21 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:43 p.m.

3.5

CVSS3.1

CVE-2025-58084 - Mattermost Desktop App crashes when clicking on malformed external URL

Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL.

πŸ“… Published: Oct. 13, 2025, 7:57 p.m. πŸ”„ Last Modified: Oct. 29, 2025, 1:34 p.m.

5.3

CVSS4.0

CVE-2025-62241 -

Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authenticated users to from one virtual instance to view the shipment addresses of different virtual instance via the _com_liferay_commerce_order_web_internal_portl…

πŸ“… Published: Oct. 13, 2025, 7:32 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:22 p.m.

5.3

CVSS4.0

CVE-2025-62242 -

Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to from one account to view addresses fr…

πŸ“… Published: Oct. 13, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 7:11 p.m.

7.5

CVSS3.1

CVE-2025-62170 - rAthena map-server use-after-free vulnerability in RODEX

rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality of rAthena's map-server in versions prior to commit af2f3ba. An unauthenticated attacker can exploit this vulnerability via a specific attacking scenario to cause a denial of ser…

πŸ“… Published: Oct. 13, 2025, 5:45 p.m. πŸ”„ Last Modified: Oct. 27, 2025, 4:11 p.m.
Total resulsts: 349182
Page 3458 of 34,919
Β« previous page Β» next page
Filters