4

CVSS3.1

CVE-2025-25201 - Improper Validation of Admin Key in PIV Smartcard

Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled prior to 1.8.0, the PIV application could accept invalid keys for authentication of the admin key. This could lead to compromise of the integrity of the data stored in the applicatiโ€ฆ

๐Ÿ“… Published: Feb. 12, 2025, 6:07 p.m. ๐Ÿ”„ Last Modified: Feb. 12, 2025, 7:28 p.m.

5.3

CVSS4.0

CVE-2025-1214 - pihome-shc PiHome Role-Based Access Control user_accounts.php authorization

A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of the component Role-Based Access Control. The manipulation leads to missing authorization. It is possible to initiate the attack remotely. The exploit haโ€ฆ

๐Ÿ“… Published: Feb. 12, 2025, 6 p.m. ๐Ÿ”„ Last Modified: Oct. 17, 2025, 3:18 p.m.

9.2

CVSS4.0

CVE-2025-25200 - Koa has Inefficient Regular Expression Complexity

Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the `X-Forwarded-Proto` and `X-Forwarded-Host` HTTP headers. This can be exploited to carry out a Denial-of-Service attack. Versions 0.2โ€ฆ

๐Ÿ“… Published: Feb. 12, 2025, 5:59 p.m. ๐Ÿ”„ Last Modified: Jan. 20, 2026, 2:42 p.m.

7.5

CVSS3.1

CVE-2025-25199 - BCryptGenerateSymmetricKey memory leak

go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41, calls to `cng.TLS1PRF` don't release the key handle, producing a small memory leak every time. Commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41 cโ€ฆ

๐Ÿ“… Published: Feb. 12, 2025, 5:49 p.m. ๐Ÿ”„ Last Modified: Feb. 12, 2025, 7:50 p.m.

7.1

CVSS3.1

CVE-2025-25198 - mailcow: dockerized vulnerable to password reset poisoning

mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to manipulate the `Host HTTP` header to generate a password reset link pointing to an attacker-controlled domain. Thisโ€ฆ

๐Ÿ“… Published: Feb. 12, 2025, 5:46 p.m. ๐Ÿ”„ Last Modified: Oct. 1, 2025, 5:39 p.m.

5.3

CVSS3.1

CVE-2024-6097 - Absolute Path Traversal Vulnerability

In Progressยฎ Telerikยฎ Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.

๐Ÿ“… Published: Feb. 12, 2025, 5:37 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2025, 4:31 p.m.

5.1

CVSS4.0

CVE-2025-1213 - pihome-shc PiHome index.php cross site scripting

A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The exploit hโ€ฆ

๐Ÿ“… Published: Feb. 12, 2025, 5:31 p.m. ๐Ÿ”„ Last Modified: Oct. 17, 2025, 3:18 p.m.

0.0

CVE-2025-1258 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: Feb. 12, 2025, 5:22 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2025, 6:15 p.m.

5.3

CVSS4.0

CVE-2025-1210 - code-projects Wazifa System control.php sql injection

A vulnerability classified as critical was found in code-projects Wazifa System 1.0. Affected by this vulnerability is an unknown functionality of the file /controllers/control.php. The manipulation of the argument to leads to sql injection. The attack can be launched remotely. The exploit has beenโ€ฆ

๐Ÿ“… Published: Feb. 12, 2025, 5 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2025, 7:03 p.m.

5.1

CVSS4.0

CVE-2025-1209 - code-projects Wazifa System search_resualts.php searchuser cross site scripting

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The expโ€ฆ

๐Ÿ“… Published: Feb. 12, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2025, 7:04 p.m.
Total resulsts: 343970
Page 6237 of 34,397
ยซ previous page ยป next page
Filters