0.0

CVE-2025-63950 -

An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that is passed directly to the unserialize() function without validati…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:21 p.m.

0.0

CVE-2025-65559 -

An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID address-family flag(s) (IPv4…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 6:42 p.m.

0.0

CVE-2025-63388 -

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any ext…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:28 p.m.

0.0

CVE-2025-63387 -

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous a…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 6:20 p.m.

0.0

CVE-2025-65567 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Session Establishment Request with a CreatePDR that contains a malformed Flow-Description is not robustly validated. The Fl…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:01 p.m.

0.0

CVE-2025-65564 -

A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory Recovery Time Stamp Information Element, the association setup handler dereferences a nil pointer…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 6:55 p.m.

0.0

CVE-2025-67163 -

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:10 p.m.

0.0

CVE-2025-63947 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:14 p.m.

0.0

CVE-2025-63948 -

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:18 p.m.

0.0

CVE-2025-63949 -

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:26 p.m.
Total resulsts: 323431
Page 45 of 32,344
Β« previous page Β» next page
Filters