6.9

CVSS4.0

CVE-2025-67513 - FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module R…

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local…

📅 Published: Dec. 10, 2025, 10:43 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:43 p.m.

8.4

CVSS3.1

CVE-2025-67505 - Race condition in the Okta Java SDK

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request…

📅 Published: Dec. 10, 2025, 10:19 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:19 p.m.

5.4

CVSS3.1

CVE-2025-67490 - Auth0 Next.js SDK has Improper Request Caching Lookup

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in ver…

📅 Published: Dec. 10, 2025, 10:16 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2025-66628 - ImageMagick is vulnerable to an Integer Overflow in TIM decoder leading to out of bounds read (32-b…

ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the …

📅 Published: Dec. 10, 2025, 10:04 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:04 p.m.

8.7

CVSS4.0

CVE-2025-66474 - XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injecti…

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 have insufficient protection against {{/html}} injection, whic…

📅 Published: Dec. 10, 2025, 9:59 p.m. 🔄 Last Modified: Dec. 10, 2025, 9:59 p.m.

8.7

CVSS4.0

CVE-2025-66473 - XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikis

XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any limits for the number of items that can be requested in a single request at the moment. Depending on the number of page…

📅 Published: Dec. 10, 2025, 9:51 p.m. 🔄 Last Modified: Dec. 10, 2025, 9:51 p.m.

5.3

CVSS3.1

CVE-2025-66033 - Improper Memory Cleanup in the Okta Java SDK

Okta Java Management SDK is facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and a…

📅 Published: Dec. 10, 2025, 9:46 p.m. 🔄 Last Modified: Dec. 10, 2025, 9:46 p.m.

6.5

CVSS4.0

CVE-2025-66472 - XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates are vulnerable to a reflected XSS attack …

📅 Published: Dec. 10, 2025, 9:34 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2024-58285 - Chyrp 2.5.2 Stored Cross-Site Scripting Vulnerability via Post Title

Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attackers can craft payloads in the title field that will execute when the post is viewed by other users, potentially stealing session cookies or performing…

📅 Published: Dec. 10, 2025, 9:15 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:16 p.m.

8.6

CVSS4.0

CVE-2024-58284 - PopojiCMS 2.0.1 Remote Command Execution via Authenticated Metadata Settings

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands throu…

📅 Published: Dec. 10, 2025, 9:15 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:16 p.m.
Total resulsts: 321707
Page 4 of 32,171
« previous page » next page
Filters