8.8

CVSS3.1

CVE-2025-64106 - Cursor: Speedbump Modal Bypass in MCP Server Deep-Link

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables specially crafted deep-links to bypass the standard security warnings and conceal executed commands from users if they choose to accept the serve…

πŸ“… Published: Nov. 4, 2025, 10:48 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 5:48 p.m.

8.2

CVSS4.0

CVE-2025-59595 -

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.

πŸ“… Published: Nov. 4, 2025, 10:46 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

8.7

CVSS4.0

CVE-2025-62722 - LinkAce: Stored XSS Vulnerability in Link Title Field Through Social Media Sharing Feature

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) vulnerability that allows any authenticated user to inject arbitrary JavaScript by creating a link with malicious HTML in the t…

πŸ“… Published: Nov. 4, 2025, 10:31 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

7.1

CVSS4.0

CVE-2025-62721 - LinkAce: Authorization Bypass Allows Unauthorized Access to All Private Links, Lists, and Tags

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement proper authorization checks, allowing any authenticated user to access all links, lists, and tags from all users in the system, rega…

πŸ“… Published: Nov. 4, 2025, 10:07 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

7.1

CVSS4.0

CVE-2025-62720 - LinkAce: Data Exfiltration via Export Functions Allow Access to All Users' Private Links

LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from all users in the system, including private links that should only be accessible to their owners. The HTML and CSV export functions in the Expo…

πŸ“… Published: Nov. 4, 2025, 10:03 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

2.3

CVSS4.0

CVE-2025-62719 - LinkAce: Limited Server-Side Request Forgery (SSRF) in Keyword Fetching Functionality

LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function in the FetchController class accepts user-provided URLs and makes HTTP requests to them without validating that the destination is not an internal or private network resource. Th…

πŸ“… Published: Nov. 4, 2025, 9:57 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

8.4

CVSS4.0

CVE-2025-54526 - Fuji Electric Monitouch V-SFT-6 Stack-based Buffer Overflow

Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

πŸ“… Published: Nov. 4, 2025, 9:37 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

5.3

CVSS4.0

CVE-2025-62715 - ClipBucket v5: Stored XSS via Collection Tags

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Scripting (XSS) vulnerability in ClipBucket’s Collection tags feature. An authenticated normal user can create a tag containing HTML or JavaScript, which is later rendered unescaped in …

πŸ“… Published: Nov. 4, 2025, 9:37 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 6:20 p.m.

8.4

CVSS4.0

CVE-2025-54496 - Fuji Electric Monitouch V-SFT-6 Heap-based Buffer Overflow

A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which may allow the attacker to execute arbitrary code.

πŸ“… Published: Nov. 4, 2025, 9:36 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

5.3

CVSS4.0

CVE-2025-62520 - MantisBT unauthorized disclosure of private project column configuration

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access to manage_config_columns_page.php can use the Copy From action to retrieve the columns configuration from a private project they have …

πŸ“… Published: Nov. 4, 2025, 9:31 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.
Total resulsts: 317435
Page 53 of 31,744
Β« previous page Β» next page
Filters