7.2

CVSS3.1

CVE-2025-68461 - roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG animate …

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

πŸ“… Published: Dec. 18, 2025, 5 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 6:53 p.m.

7.2

CVSS3.1

CVE-2025-68460 - roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

πŸ“… Published: Dec. 18, 2025, 4:54 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 6:53 p.m.

6.4

CVSS3.1

CVE-2025-12885 - Embed Any Document <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function regex bypass in all versions up to, and including, 2.7.10 due to insufficient input sanitization and output escaping. This makes i…

πŸ“… Published: Dec. 18, 2025, 1:51 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 1:51 a.m.

5.3

CVSS4.0

CVE-2025-14856 - y_project RuoYi getnames code injection

A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicl…

πŸ“… Published: Dec. 18, 2025, 1:32 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 1:32 a.m.

4.8

CVSS4.0

CVE-2025-14841 - OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference

A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. This manipulation causes null point…

πŸ“… Published: Dec. 18, 2025, 12:02 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 12:02 a.m.

0.0

CVE-2025-63388 -

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any ext…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 9:29 p.m.

0.0

CVE-2025-63390 -

An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed information about all configured workspaces. Exposed da…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 9:27 p.m.

7.5

CVSS3.1

CVE-2025-65567 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Session Establishment Request with a CreatePDR that contains a malformed Flow-Description is not robustly validated. The Fl…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6:15 p.m.

7.5

CVSS3.1

CVE-2025-65565 -

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session Establishment Request that is missing the mandatory F-SEID (CPF-SEID) Information Element is not properly validated. T…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6:15 p.m.

7.5

CVSS3.1

CVE-2025-65562 -

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNod…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6:15 p.m.
Total resulsts: 323547
Page 55 of 32,355
Β« previous page Β» next page
Filters