0.0

CVE-2025-63386 -

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains t…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 9:24 p.m.

0.0

CVE-2025-63388 -

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any ext…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 9:29 p.m.

0.0

CVE-2025-63947 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:14 p.m.

0.0

CVE-2025-65565 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session Establishment Request that is missing the mandatory F-SEID (CPF-SEID) Information Element is not properly validated. T…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 6:57 p.m.

0.0

CVE-2025-65564 -

A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory Recovery Time Stamp Information Element, the association setup handler dereferences a nil pointer…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 6:55 p.m.

0.0

CVE-2025-65559 -

An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID address-family flag(s) (IPv4…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 6:42 p.m.

0.0

CVE-2025-65563 -

A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferen…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 6:52 p.m.

0.0

CVE-2025-67163 -

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:10 p.m.

0.0

CVE-2025-63389 -

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:13 p.m.

0.0

CVE-2025-63948 -

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:18 p.m.
Total resulsts: 323511
Page 53 of 32,352
Β« previous page Β» next page
Filters