0.0

CVE-2025-63947 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:14 p.m.

7.5

CVSS3.1

CVE-2025-65563 -

A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferen…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 6:15 p.m.

0.0

CVE-2025-67163 -

A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:10 p.m.

0.0

CVE-2025-63948 -

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:18 p.m.

0.0

CVE-2025-63951 -

An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. T…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:28 p.m.

0.0

CVE-2025-63950 -

An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that is passed directly to the unserialize() function without validati…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:21 p.m.

0.0

CVE-2025-63391 -

An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:23 p.m.

0.0

CVE-2025-63386 -

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains t…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 9:24 p.m.

8.2

CVSS4.0

CVE-2025-14202 - Cross-Site Request Forgery (CSRF) Leading to Account Takeover via SVG File Upload

A vulnerability in the file upload at bookmark + asset rendering pipeline allows an attacker to upload a malicious SVG file with JavaScript content. When an authenticated admin user views the SVG file with embedded JavaScript code of shared bookmark, JavaScript executes in the admin’s browser, retr…

πŸ“… Published: Dec. 17, 2025, 11:35 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 11:35 p.m.

5.1

CVSS4.0

CVE-2025-14837 - ZZCMS Backend Website Settings siteconfig.php stripfxg code injection

A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Backend Website Settings Module. Such manipulation of the argument icp leads to code injection. The attack can be executed remotely. The exploit has been …

πŸ“… Published: Dec. 17, 2025, 11:32 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 11:32 p.m.
Total resulsts: 323547
Page 57 of 32,355
Β« previous page Β» next page
Filters