6.9

CVSS4.0

CVE-2025-61775 - Vickey's unexpired email confirmation link can be reused to send repeated confirmation emails

Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unexpired email confirmation links can be reused multiple times to send repeated confirmation emails to a verified email address. Under certain conditions, a verified email address co…

πŸ“… Published: Oct. 13, 2025, 5:29 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 1:24 p.m.

5.3

CVSS4.0

CVE-2025-62243 -

Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated attackers to view publication comments via the _com_lif…

πŸ“… Published: Oct. 13, 2025, 5:14 p.m. πŸ”„ Last Modified: Oct. 13, 2025, 6:15 p.m.

4.8

CVSS4.0

CVE-2025-62244 -

Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92, and 7.3 GA through update 36 allows remote authenticated attackers to view the edi…

πŸ“… Published: Oct. 13, 2025, 4:53 p.m. πŸ”„ Last Modified: Oct. 13, 2025, 5:15 p.m.

8

CVSS3.1

CVE-2025-11695 - Configuration may unexpectedly disable certificate validation

When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5

πŸ“… Published: Oct. 13, 2025, 4:22 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 7:36 p.m.

7.1

CVSS3.0

CVE-2025-7707 - World-Writable NLTK Cache Directory Vulnerability in run-llama/llama_index

The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-user environments. This configuration allows local users to overwrite, delete, or corrupt NLTK data files, leading to potential denial of service, data…

πŸ“… Published: Oct. 13, 2025, 4:15 p.m. πŸ”„ Last Modified: Oct. 13, 2025, 5:15 p.m.

6.3

CVSS3.1

CVE-2025-43991 -

SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A low privileged attacker with local access to the system could potentially exploit this vulnerability to delete arbitrar…

πŸ“… Published: Oct. 13, 2025, 2:30 p.m. πŸ”„ Last Modified: Oct. 13, 2025, 4:18 p.m.

9.1

CVSS3.1

CVE-2025-37729 - Elastic Cloud Enterprise (ECE) Improper Neutralization of Special Elements Used in a Template Engine

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.

πŸ“… Published: Oct. 13, 2025, 1:47 p.m. πŸ”„ Last Modified: Oct. 13, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2025-9902 - IDOR in AkΔ±nsoft QRMenu

Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trade Co. Ltd. QRMenu allows Privilege Abuse.This issue affects QRMenu: from 1.05.12 before Version dated 05.09.2025.

πŸ“… Published: Oct. 13, 2025, 1:06 p.m. πŸ”„ Last Modified: Oct. 13, 2025, 1:15 p.m.

9.8

CVSS3.1

CVE-2025-6919 - SQLi in Cats Informatics' Aykome

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information Technology Software Development Technologies Aykome License Tracking System allows SQL Injection.This issue affects Aykome License Tracking System: before Version dated 06.10.2025.

πŸ“… Published: Oct. 13, 2025, 12:46 p.m. πŸ”„ Last Modified: Oct. 13, 2025, 2:15 p.m.

0.0

CVE-2025-10720 - WP Private Content Plus <= 3.6.2 - Password Protection Bypass

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protecti…

πŸ“… Published: Oct. 13, 2025, 9:37 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 7:36 p.m.
Total resulsts: 314252
Page 43 of 31,426
Β« previous page Β» next page
Filters