5.3

CVSS4.0

CVE-2025-11490 - wonderwhy-er DesktopCommanderMCP Absolute Path command-manager.ts extractBaseCommand os command inj…

A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute Path Handler. Such manipulation leads to os command injection. The attack may be performed from remot…

πŸ“… Published: Oct. 8, 2025, 6:32 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 6:32 p.m.

2.3

CVSS4.0

CVE-2025-61906 - Opencast's editor accidentally publishes videos/overwrites publications #1626

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, in some situations, Opencast's editor may publish a video without notifying the user. This may lead to users accidentally publishing media not meant for publis…

πŸ“… Published: Oct. 8, 2025, 6:06 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 6:06 p.m.

5.1

CVSS4.0

CVE-2025-61788 - Opencast Paella Player 7 vulnerable to Cross-Site-Scripting

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, the paella would include and render some user inputs (metadata like title, description, etc.) unfiltered and unmodified. The vulnerability allows attackers to …

πŸ“… Published: Oct. 8, 2025, 6:03 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 6:03 p.m.

2

CVSS4.0

CVE-2025-11489 - wonderwhy-er DesktopCommanderMCP filesystem.ts isPathAllowed symlink

A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads to symlink following. The attack can only be performed from a local environment. The attack'…

πŸ“… Published: Oct. 8, 2025, 6:02 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 6:02 p.m.

6.9

CVSS4.0

CVE-2025-11488 - D-Link DIR-852 HNAP1 command injection

A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Executing manipulation can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. This vulnerability …

πŸ“… Published: Oct. 8, 2025, 6:02 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 6:02 p.m.

5.3

CVSS4.0

CVE-2025-11487 - SourceCodester Farm Management System uploadProduct.php sql injection

A security flaw has been discovered in SourceCodester Farm Management System 1.0. Affected by this issue is some unknown functionality of the file /uploadProduct.php. Performing manipulation of the argument Type results in sql injection. The attack may be initiated remotely. The exploit has been re…

πŸ“… Published: Oct. 8, 2025, 5:32 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 5:32 p.m.

5.6

CVSS3.1

CVE-2025-42701 - CrowdStrike Falcon Sensor for Windows Race Condition

A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Support (LTS)…

πŸ“… Published: Oct. 8, 2025, 5:18 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 5:22 p.m.

6.5

CVSS3.1

CVE-2025-42706 - CrowdStrike Falcon Sensor for Windows Logic Error

A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Support (LTS) se…

πŸ“… Published: Oct. 8, 2025, 5:18 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 5:24 p.m.

8.7

CVSS4.0

CVE-2025-9868 - Nexus Repository 2 - SSRF Vulnerability in Remote Browser Plugin

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

πŸ“… Published: Oct. 8, 2025, 5:07 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 5:23 p.m.

5.3

CVSS4.0

CVE-2025-11486 - SourceCodester Farm Management System buyNow.php sql injection

A vulnerability was identified in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /buyNow.php. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit is publicly available and …

πŸ“… Published: Oct. 8, 2025, 5:02 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 5:15 p.m.
Total resulsts: 313404
Page 6 of 31,341
Β« previous page Β» next page
Filters