7.5

CVSS3.1

CVE-2025-63391 -

An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 9:18 a.m.

5.5

CVSS3.1

CVE-2025-68324 - scsi: imm: Fix use-after-free bug caused by unfinished delayed work

In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item 'imm_tq' is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands. When the IMM parallel port SCSI…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:16 p.m.

0.0

CVE-2025-65566 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Session Report Response that is missing the mandatory Cause Information Element, the session report handler dereferences a nil pointer instead …

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.

7.5

CVSS3.1

CVE-2025-63951 -

An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. T…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2025-63950 -

An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that is passed directly to the unserialize() function without validati…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 10:15 p.m.

0.0

CVE-2025-68325 - net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop In cake_drop(), qdisc_tree_reduce_backlog() is used to update the qlen and backlog of the qdisc hierarchy. Its caller, cake_enqueue(), assumes that the parent qdisc w…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:16 p.m.

7.5

CVSS3.1

CVE-2025-63757 - ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 9:18 a.m.

6.1

CVSS3.1

CVE-2025-63949 -

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 10:15 p.m.

0.0

CVE-2025-65563 -

A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferen…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:16 p.m.

0.0

CVE-2025-65562 -

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNod…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 9:18 a.m.
Total resulsts: 323442
Page 46 of 32,345
Β« previous page Β» next page
Filters