9.4

CVSS3.0

CVE-2025-10644 - Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability

Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability. The specific flaw exists within the permissโ€ฆ

๐Ÿ“… Published: Sept. 17, 2025, 8:41 p.m. ๐Ÿ”„ Last Modified: Sept. 19, 2025, 12:58 p.m.

9.1

CVSS3.0

CVE-2025-10643 - Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability

Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required to exploit this vulnerability. The specific flaw exists wiโ€ฆ

๐Ÿ“… Published: Sept. 17, 2025, 8:41 p.m. ๐Ÿ”„ Last Modified: Sept. 19, 2025, 12:59 p.m.

5.3

CVSS4.0

CVE-2025-10617 - SourceCodester Online Polling System positions.php sql injection

A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/positions.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made availabโ€ฆ

๐Ÿ“… Published: Sept. 17, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Sept. 20, 2025, 2:40 a.m.

5.3

CVSS4.0

CVE-2025-10616 - itsourcecode E-Commerce Website users.php unrestricted upload

A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

๐Ÿ“… Published: Sept. 17, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Sept. 20, 2025, 2:40 a.m.

5.3

CVSS4.0

CVE-2025-10615 - itsourcecode E-Commerce Website products.php unrestricted upload

A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit is publicly available and might be used.

๐Ÿ“… Published: Sept. 17, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: Sept. 20, 2025, 2:41 a.m.

9.8

CVSS3.1

CVE-2025-59340 - jinjava Sandbox Bypass via JavaType-Based Deserialization

jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonical(), it is possible to instruct the underlying ObjectMapper to deserialize attacker-controlled input into arbitrary clasโ€ฆ

๐Ÿ“… Published: Sept. 17, 2025, 8:01 p.m. ๐Ÿ”„ Last Modified: Sept. 26, 2025, 1:11 p.m.

5.5

CVSS4.0

CVE-2025-59410 - Dragonfly tiny file download uses hard coded HTTP protocol

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an attacker could perform a Man-in-the-Middle attack, changing the โ€ฆ

๐Ÿ“… Published: Sept. 17, 2025, 7:58 p.m. ๐Ÿ”„ Last Modified: Sept. 18, 2025, 4:54 p.m.

5.5

CVSS4.0

CVE-2025-59354 - Dragonfly has weak integrity checks for downloaded files

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the MD5 hash, for downloaded files. This allows attackers to replace files with malicious ones that have a colliding hash. This vulnerabiโ€ฆ

๐Ÿ“… Published: Sept. 17, 2025, 7:57 p.m. ๐Ÿ”„ Last Modified: Sept. 18, 2025, 8:08 p.m.

7.7

CVSS4.0

CVE-2025-59353 - Manager generates mTLS certificates for arbitrary IP addresses

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue is that the Managerโ€™s Certificate gRPC service does not validโ€ฆ

๐Ÿ“… Published: Sept. 17, 2025, 7:53 p.m. ๐Ÿ”„ Last Modified: Sept. 18, 2025, 8:08 p.m.

6.9

CVSS4.0

CVE-2025-59352 - Dragonfly allows arbitrary file read and write on a peer machine

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send requests that force the recipient peer to create files in arbitrary file system locations, and to read arbitrary files. This allows peers to steal otโ€ฆ

๐Ÿ“… Published: Sept. 17, 2025, 7:50 p.m. ๐Ÿ”„ Last Modified: Sept. 18, 2025, 8:09 p.m.
Total resulsts: 349182
Page 3802 of 34,919
ยซ previous page ยป next page
Filters