5

CVSS3.1

CVE-2025-66407 - Weblate has Server-Side Request Forgery vulnerability

Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, prior to version 5.15, the repository URL field is no…

πŸ“… Published: Dec. 15, 2025, 11:36 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.

7.8

CVSS3.1

CVE-2025-9455 - CATPRODUCT File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Dec. 15, 2025, 11:35 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.

7.8

CVSS3.1

CVE-2025-9454 - PRT File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Dec. 15, 2025, 11:34 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.

7.8

CVSS3.1

CVE-2025-9453 - PRT File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Dec. 15, 2025, 11:33 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.

7.8

CVSS3.1

CVE-2025-9452 - SLDPRT File Parsing Memory Corruption Vulnerability

A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

πŸ“… Published: Dec. 15, 2025, 11:32 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.

5.3

CVSS4.0

CVE-2025-14731 - CTCMS Content Management System Frontend/Template Management CT_Parser.php special elements used in…

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special elements used in a tem…

πŸ“… Published: Dec. 15, 2025, 11:32 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.

7.8

CVSS3.1

CVE-2025-14593 - CATPART File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Dec. 15, 2025, 11:31 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.

6.9

CVSS4.0

CVE-2025-66482 - Misskey has a login rate limit bypass via spoofed X-Forwarded-For header

Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.9.1, an option (`trustProxy`) has been added in config file …

πŸ“… Published: Dec. 15, 2025, 11:18 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.

7.1

CVSS4.0

CVE-2025-66402 - misskey.js's export data contains private post data

Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission to view favorites or clips can can export the posts and view the contents. Version 2025.12.0 fixes the issue.

πŸ“… Published: Dec. 15, 2025, 11:09 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.

7.4

CVSS4.0

CVE-2025-58173 - FreshRSS vulnerable to authenticated RCE via path traversal inside include()

FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it's possible to call `install.php` and perform various administrative actions as an unprivileged user. These actions include logging in as th…

πŸ“… Published: Dec. 15, 2025, 11:07 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 12:16 a.m.
Total resulsts: 322764
Page 38 of 32,277
Β« previous page Β» next page
Filters