5.4

CVSS3.1

CVE-2025-47910 - CrossOriginProtection insecure bypass patterns not limited to exact matches in net/http

When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.

๐Ÿ“… Published: Sept. 22, 2025, 9:01 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-59535 - DotNetNuke.Core allows loading of unused themes on anonymous clients through query parameters

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, 8:59 p.m. ๐Ÿ”„ Last Modified: Sept. 29, 2025, 12:53 p.m.

5.3

CVSS4.0

CVE-2025-10814 - D-Link DIR-823X goahead command injection

A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/goahead. This manipulation of the argument port causes command injection. The attack can be initiated remotely. The exploit has been publicly discโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Sept. 24, 2025, 6:42 p.m.

8.6

CVSS4.0

CVE-2025-59532 - Codex has sandbox bypass due to bug in path configuration logic

Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox configuration logic, Codex CLI could treat a model-generated cwd as the sandboxโ€™s writable root, including paths outside of the folder where the user started their session. This logicโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, 8:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10813 - code-projects Hostel Management System index.php sql injection

A vulnerability was found in code-projects Hostel Management System 1.0. Affected is an unknown function of the file /justines/admin/mod_reports/index.php. The manipulation of the argument Home results in sql injection. It is possible to launch the attack remotely. The exploit has been made public โ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2025, 4:47 p.m.

10

CVSS3.1

CVE-2025-59528 - Flowise has Remote Code Execution vulnerability

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, 7:54 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2025, 4:45 p.m.

7.5

CVSS3.1

CVE-2025-59527 - FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulnerability was discovered in the /api/v1/fetch-links endpoint of the Flowise application. This vulnerability allows an attacker to use the Flowise serveโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, 7:48 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2025, 4:47 p.m.

9.6

CVSS3.1

CVE-2025-59434 - Critical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript Function

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated vulnerability in Flowise Cloud allows any user on the free tier to access sensitive environment variables from other tenants via the Custom JavaScriptโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, 7:39 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10812 - code-projects Hostel Management System index.php sql injection

A vulnerability has been found in code-projects Hostel Management System 1.0. This impacts an unknown function of the file /justines/admin/mod_amenities/index.php?view=view. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has bโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: Sept. 23, 2025, 4:48 p.m.

2.7

CVSS4.0

CVE-2025-59526 - Mailgen: HTML injection vulnerability in plaintext e-mails

mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Prior to version 2.0.30, there is an HTML injection vulnerability in plaintext e-mails generated by Mailgen. Projects are affected if the Mailgen.generatePlaintext(email) method is used and given useโ€ฆ

๐Ÿ“… Published: Sept. 22, 2025, 7:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3718 of 34,919
ยซ previous page ยป next page
Filters