2.7

CVSS4.0

CVE-2025-59351 - Dragonfly possibly panics due to nil pointer dereference when using variables created alongside an …

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even when the function returns an error. This can result in a nil dereference, and cause code to panic. This vulnerability is fixed in 2.1.0.

📅 Published: Sept. 17, 2025, 7:46 p.m. 🔄 Last Modified: Sept. 18, 2025, 8:09 p.m.

2.7

CVSS4.0

CVE-2025-59350 - Timing attacks against Proxy’s basic authentication are possible

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access control mechanism for the Proxy feature uses simple string comparisons and is therefore vulnerable to timing attacks. An attacker may try to guess the password one character at a time b…

📅 Published: Sept. 17, 2025, 7:43 p.m. 🔄 Last Modified: Sept. 18, 2025, 8:15 p.m.

2

CVSS4.0

CVE-2025-59349 - Directories created via os.MkdirAll are not checked for permissions

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, DragonFly2 uses the os.MkdirAll function to create certain directory paths with specific access permissions. This function does not perform any permission checks when a given directory path alread…

📅 Published: Sept. 17, 2025, 7:41 p.m. 🔄 Last Modified: Sept. 18, 2025, 8:17 p.m.

5.3

CVSS4.0

CVE-2025-10614 - itsourcecode E-Logbook with Health Monitoring System for COVID-19 print_reports_prev.php cross site…

A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of the file /print_reports_prev.php. Executing manipulation of the argument profile_id can lead to cross site scripting. It is possible to launch the at…

📅 Published: Sept. 17, 2025, 7:32 p.m. 🔄 Last Modified: Sept. 20, 2025, 2:41 a.m.

6.1

CVSS3.1

CVE-2025-37122 - Unauthenticated Reflected Cross-Site Scripting

A vulnerability in the web-based management interface of network access control services could allow an unauthenticated remote attacker to conduct a Reflected Cross-Site Scripting (XSS) attack. Successful exploitation could allow an attacker to execute arbitrary JavaScript code in a victim's browse…

📅 Published: Sept. 17, 2025, 7:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS4.0

CVE-2025-59348 - Dragonfly incorrectly handles a task structure’s usedTraffic field

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not update the structure’s usedTraffic field, because an uninitialized variable n is used as a guard to the AddTraffic method call, instead of the result.Siz…

📅 Published: Sept. 17, 2025, 7:30 p.m. 🔄 Last Modified: Sept. 18, 2025, 8:18 p.m.

2.7

CVSS4.0

CVE-2025-59347 - Dragonfly Manager makes requests to external endpoints with disabled TLS authentication

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clients are not configurable, so users have no way to re-enable the verification. A Manager processes dozens of preheat jobs.…

📅 Published: Sept. 17, 2025, 7:23 p.m. 🔄 Last Modified: Sept. 18, 2025, 8:19 p.m.

5.5

CVSS4.0

CVE-2025-59346 - Dragonfly server-side request forgery vulnerability

Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery (SSRF) vulnerability that enables users to force DragonFly2’s components to make requests to internal services that are otherwise not accessible to th…

📅 Published: Sept. 17, 2025, 7:20 p.m. 🔄 Last Modified: Sept. 18, 2025, 8:20 p.m.

7.7

CVSS4.0

CVE-2025-59345 - Dragonfly did not enable authentication for some Manager’s endpoints

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible without authentication. Any user with network access to the Manager can create, delete, and modify jobs, and create prehea…

📅 Published: Sept. 17, 2025, 7:05 p.m. 🔄 Last Modified: Oct. 13, 2025, 4:15 p.m.

5.3

CVSS4.0

CVE-2025-10613 - itsourcecode Student Information System leveledit1.php sql injection

A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /leveledit1.php. Such manipulation of the argument level_id leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the p…

📅 Published: Sept. 17, 2025, 7:02 p.m. 🔄 Last Modified: Sept. 20, 2025, 2:42 a.m.
Total resulsts: 349182
Page 3803 of 34,919
« previous page » next page
Filters