0.0

CVE-2025-39799 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Sept. 12, 2025, 3:59 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 6:10 a.m.

5.3

CVSS4.0

CVE-2025-10319 - JeecgBoot Tenant Log Export exportLog improper authorization

A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Export. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been rele…

πŸ“… Published: Sept. 12, 2025, 3:02 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 1:53 a.m.

9.3

CVSS4.0

CVE-2025-10364 - Unauthenticated Arbitrary Command Injection in Evertz SDVN

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup network switching, and register license among ot…

πŸ“… Published: Sept. 12, 2025, 1:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-10365 - Authentication Bypass in Evertz SDVN

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes aΒ web management interface on port 80. This web management interface can be used by administrators to control product features, setup network switching, and register license among ot…

πŸ“… Published: Sept. 12, 2025, 1:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-9556 - CVE-2025-9556

Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a st…

πŸ“… Published: Sept. 12, 2025, 1:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-59058 - httpsig-rs's HMAC verification is vulnerable to timing attack

httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signature comparison is not timing-safe. This makes anyone who uses HS256 signature verification vulnerable to a timing attack that allows the attacker to forge a signature. Version 0.0.1…

πŸ“… Published: Sept. 12, 2025, 1:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-59139 - Hono has Body Limit Middleware Bypass

Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were present. The middleware previously prioritized the `…

πŸ“… Published: Sept. 12, 2025, 1:03 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 8:35 p.m.

8.5

CVSS4.0

CVE-2025-59054 - dstack has insecure LUKS2 persistent storage partitions that may be opened and used

dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execution environments. In versions of dstack prior to 0.5.4, a malicious host may provide a crafted LUKS2 data volume to a dstack CVM for use as the `/data` mount. The guest will open…

πŸ“… Published: Sept. 12, 2025, 1:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10318 - JeecgBoot WebSocket Message sendWebSocketMsg improper authorization

A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler. The manipulation of the argument userIds leads to improper authorization. The attack can be initia…

πŸ“… Published: Sept. 12, 2025, 12:32 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 1:53 a.m.

9.1

CVSS3.1

CVE-2025-8699 -

Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use this vulnerability to change the balance on the cards and generate money. The account balance is stored on an insecure MiFare Classic NFC card and can be read and written back.Β By c…

πŸ“… Published: Sept. 12, 2025, 11:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3891 of 34,919
Β« previous page Β» next page
Filters