0.0

CVE-2025-63948 -

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:18 p.m.

0.0

CVE-2025-63951 -

An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. T…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:28 p.m.

0.0

CVE-2025-65562 -

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNod…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 6:48 p.m.

0.0

CVE-2025-63950 -

An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that is passed directly to the unserialize() function without validati…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:21 p.m.

0.0

CVE-2025-63391 -

An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:23 p.m.

8.2

CVSS4.0

CVE-2025-14202 - Cross-Site Request Forgery (CSRF) Leading to Account Takeover via SVG File Upload

A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG file with JavaScript content. When an authenticated admin user views the SVG file with embedded JavaScript code of shared bookmark, JavaScript executes in the admin’s browser, retr…

πŸ“… Published: Dec. 17, 2025, 11:35 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 11:35 p.m.

5.1

CVSS4.0

CVE-2025-14837 - ZZCMS Backend Website Settings siteconfig.php stripfxg code injection

A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Backend Website Settings Module. Such manipulation of the argument icp leads to code injection. The attack can be executed remotely. The exploit has been …

πŸ“… Published: Dec. 17, 2025, 11:32 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 11:32 p.m.

9.1

CVSS3.1

CVE-2025-68435 - Zerobyte has Authentication Bypass by Primary Weakness

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied to API endpoints. This results in certain API endpoints being accessible without valid session credentials. This i…

πŸ“… Published: Dec. 17, 2025, 11:10 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 11:10 p.m.

5.1

CVSS4.0

CVE-2025-14836 - ZZCMS User Data Storage user_save.php cleartext storage in a file or on disk

A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes cleartext storage in a file or on disk. Remote exploitation of the attack is possible. The exploit has b…

πŸ“… Published: Dec. 17, 2025, 11:02 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 11:02 p.m.

5.3

CVSS4.0

CVE-2025-14834 - code-projects Simple Stock System checkuser.php sql injection

A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /checkuser.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and…

πŸ“… Published: Dec. 17, 2025, 11:02 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 11:02 p.m.
Total resulsts: 323512
Page 54 of 32,352
Β« previous page Β» next page
Filters