6.6

CVSS4.0

CVE-2025-61680 - Minecraft RCON Terminal: Plain Text Password Storage in Configuration

Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0.6 stores passwords using VS Code's configuration API which writes to settings.json in plaintext. This issue is fixed in version 2.1.0.

📅 Published: Oct. 3, 2025, 9:37 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.1

CVE-2025-61679 - Anyquery Unauthenticated Access Vulnerability Exposes Private Integration Data

Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained access to localhost, even with low privileges, to use the http server through the port unauthenticated, and access private integration data like emails, without any warning of a …

📅 Published: Oct. 3, 2025, 9:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.5

CVSS3.1

CVE-2025-61677 - DataChain: Deserialization of Untrusted Data from Environment Variables

DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and below allow for deseriaization of untrusted data because of the way the DataChain library reads serialized objects from environment variables (such as DATACHAIN__METASTORE and DATACHA…

📅 Published: Oct. 3, 2025, 9:18 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2025-43825 -

A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA throu…

📅 Published: Oct. 3, 2025, 9:16 p.m. 🔄 Last Modified: Dec. 15, 2025, 6:22 p.m.

8.6

CVSS3.1

CVE-2025-61673 - Karapace is vulnerable to Authentication Bypass

Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authentication bypass vulnerability when configured to use OAuth 2.0 Bearer Token authentication. If a request is sent without an Authorization header, the token validation logic is skip…

📅 Published: Oct. 3, 2025, 9:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10695 - OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauthenticated SSRF for internal network scanning and service interaction. This issue affects OpenSuppo…

📅 Published: Oct. 3, 2025, 8:39 p.m. 🔄 Last Modified: Dec. 22, 2025, 1:45 p.m.

7.1

CVSS4.0

CVE-2025-10696 - OpenSupports 4.11.0 — Insecure Direct Object Reference in supervised list

OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Level 1 staff member can modify the supervision relationship of a third party (the target user), who can then view the ti…

📅 Published: Oct. 3, 2025, 8:35 p.m. 🔄 Last Modified: Dec. 22, 2025, 1:19 p.m.

7.1

CVSS4.0

CVE-2025-10692 - OpenSupports 4.11.0 — SQL Injection

The endpoint POST /api/staff/get-new-tickets concatenates the user-controlled parameter departmentId directly into the SQL WHERE clause without parameter binding. As a result, an authenticated staff user (level ≥ 1) can inject SQL to alter the filter logic, effectively bypassing department scoping …

📅 Published: Oct. 3, 2025, 8:30 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-59944 - Cursor IDE: Sensitive File Overwrite Bypass is Possible

Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sensitive files (e.g., */.cursor/mcp.json), which allows attackers to modify the content of these files through prompt injection and achieve remote code …

📅 Published: Oct. 3, 2025, 8:15 p.m. 🔄 Last Modified: Oct. 16, 2025, 6:16 p.m.

8.1

CVSS3.1

CVE-2025-59943 - phpMyFAQ duplicate email registration allows multiple accounts with the same email

phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is often used as an identifier for password resets…

📅 Published: Oct. 3, 2025, 8:06 p.m. 🔄 Last Modified: Oct. 10, 2025, 4:35 p.m.
Total resulsts: 349182
Page 3572 of 34,919
« previous page » next page
Filters