0.0

CVE-2025-14860 - Use-after-free in the Disability Access APIs component

Use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 146.0.1.

πŸ“… Published: Dec. 18, 2025, 2:21 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 8:35 p.m.

0.0

CVE-2025-14744 - Filename spoofing via Unicode Right-to-Left Override in Firefox for iOS

Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.

πŸ“… Published: Dec. 18, 2025, 2:21 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 2:21 p.m.

7.5

CVSS3.1

CVE-2025-1029 - Hardcoded Credentials in Utarit Informatics' SoliClub

Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants Within an Executable.This issue affects SoliClub: from 5.2.4 before 5.3.7.

πŸ“… Published: Dec. 18, 2025, 2:16 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 2:16 p.m.

6.1

CVSS3.1

CVE-2025-9787 - Stored XSS

Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.

πŸ“… Published: Dec. 18, 2025, 2:14 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 2:14 p.m.

2.3

CVSS4.0

CVE-2025-65000 - Exposure of SSH Private Keys in Remote Alert Handlers (Linux) Rule

SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was deployed.

πŸ“… Published: Dec. 18, 2025, 2:04 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 2:04 p.m.

7.2

CVSS4.0

CVE-2025-40898 - Path traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths,…

πŸ“… Published: Dec. 18, 2025, 1:19 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 1:19 p.m.

5.3

CVSS4.0

CVE-2025-40893 - HTML injection in Asset List in Guardian/CMC before 25.5.0

A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the A…

πŸ“… Published: Dec. 18, 2025, 1:17 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 1:17 p.m.

7.1

CVSS4.0

CVE-2025-40892 - Stored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a ma…

πŸ“… Published: Dec. 18, 2025, 1:16 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 1:16 p.m.

2.3

CVSS4.0

CVE-2025-40891 - HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0

A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two…

πŸ“… Published: Dec. 18, 2025, 1:14 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 1:14 p.m.

4.3

CVSS3.1

CVE-2025-13110 - HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.3 - Authenticated (Subscriber+) Insec…

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.3 via the "woof_add_subscr" function due to missing validation on a user controlled key. This makes it possible for authenticat…

πŸ“… Published: Dec. 18, 2025, 12:22 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 12:22 p.m.
Total resulsts: 323602
Page 36 of 32,361
Β« previous page Β» next page
Filters