8.4

CVSS3.1

CVE-2025-14096 - Credential Disclosure vulnerability in Radiometer Products

A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possibility to extract credential information. The vulnerability is due to a weakness in the design and insufficient credential protection in operating system. Other related CVE's are…

πŸ“… Published: Dec. 17, 2025, 12:19 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 9:57 a.m.

3.1

CVSS3.1

CVE-2025-62690 - Open redirect in error page when link opened in new tab

Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.

πŸ“… Published: Dec. 17, 2025, 12:19 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 9:18 p.m.

3

CVSS3.1

CVE-2025-13352 - Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking

Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.

πŸ“… Published: Dec. 17, 2025, 12:11 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 9:18 p.m.

4.3

CVSS3.1

CVE-2025-62190 - CSRF Allows Call Initiation and Message Delivery

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a maliciou…

πŸ“… Published: Dec. 17, 2025, 12:07 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:07 p.m.

9.8

CVSS3.1

CVE-2025-67895 - Apache Airflow Providers Edge3: Edge3 Worker RPC RCE on Airflow 2

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially released, however if you installed and confi…

πŸ“… Published: Dec. 17, 2025, 11:47 a.m. πŸ”„ Last Modified: Dec. 17, 2025, 9:18 p.m.

5.7

CVSS3.1

CVE-2025-14095 - Privilege boundary violation in Radiometer Products

A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user with physical access to the analyzer, the possibility to gain unauthorized access to functionalities outside the restricted environment. The vulnerabi…

πŸ“… Published: Dec. 17, 2025, 11:45 a.m. πŸ”„ Last Modified: Dec. 17, 2025, 9:18 p.m.

7.1

CVSS3.1

CVE-2025-14101 - IDOR in GG Soft's PaperWork

Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploitation of Trusted Identifiers.This issue affects PaperWork: from 5.2.0.9427 before 6.0.

πŸ“… Published: Dec. 17, 2025, 9:11 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 6:59 a.m.

6.3

CVSS3.1

CVE-2025-14347 - Reflected XSS in Proliz's OBS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. OBS (Student Affairs Information System)0 allows Reflected XSS.This issue affects OBS (Student Affairs Information System)0: before 26.5009.

πŸ“… Published: Dec. 17, 2025, 8:12 a.m. πŸ”„ Last Modified: Dec. 17, 2025, 9:45 p.m.

4.3

CVSS3.1

CVE-2025-14399 - Download Plugins and Themes from Dashboard <= 1.9.6 - Cross-Site Request Forgery to Bulk Plugin/The…

The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possi…

πŸ“… Published: Dec. 17, 2025, 7:21 a.m. πŸ”„ Last Modified: Dec. 17, 2025, 9:44 p.m.

4.9

CVSS3.1

CVE-2025-12496 - Zephyr Project Manager <= 3.3.203 - Authenticated (Custom+) Arbitrary File Read And Server-Side Req…

The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the `file` parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server,…

πŸ“… Published: Dec. 17, 2025, 7:21 a.m. πŸ”„ Last Modified: Dec. 17, 2025, 9:43 p.m.
Total resulsts: 323547
Page 70 of 32,355
Β« previous page Β» next page
Filters