6.5

CVSS3.1

CVE-2025-55341 -

Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad.

πŸ“… Published: Nov. 5, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

5.3

CVSS3.1

CVE-2025-59716 -

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail address corresponds to a valid pending guest use…

πŸ“… Published: Nov. 5, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

5.5

CVSS3.1

CVE-2025-60753 - libarchive: bsdtar hangs and OOMs with zero-length pattern matches

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).

πŸ“… Published: Nov. 5, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

5.3

CVSS3.1

CVE-2025-55342 -

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.

πŸ“… Published: Nov. 5, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

9.8

CVSS3.1

CVE-2025-61304 -

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.

πŸ“… Published: Nov. 5, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 7:45 p.m.

9.1

CVSS3.1

CVE-2025-63416 -

** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authenticated low-privileged attackers to execute arbitrary JavaScript in the context of other users' sessions. This can be exploited to access adminis…

πŸ“… Published: Nov. 5, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 7:47 p.m.

5.4

CVSS3.1

CVE-2025-57244 -

OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts script tags and the Email field is vulnerable when the POST request is modified to include encoded script tags, by passing frontend validation.

πŸ“… Published: Nov. 5, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 7:48 p.m.

7.3

CVSS4.0

CVE-2025-31133 - runc container escape via "masked path" abuse due to mount race conditions

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was a…

πŸ“… Published: Nov. 5, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:19 p.m.

8.7

CVSS4.0

CVE-2025-64110 - Cursor: Authentication Bypass Possible via New Cursorignore Write

Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive files that should be protected via cursorignore. An attacker who has already achieved prompt injection, or a malicious model, could create a new cursorignore f…

πŸ“… Published: Nov. 4, 2025, 11:24 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 2:26 p.m.

8.8

CVSS3.1

CVE-2025-64109 - Cursor CLI Beta: Command Injection via Untrusted MCP Configuration

Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta allowed an attacker to achieve remote code execution through the MCP (Model Context Protocol) server mechanism by uploading a malicious MCP configuration in .cursor/mcp.json file in …

πŸ“… Published: Nov. 4, 2025, 11:09 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 2:26 p.m.
Total resulsts: 317640
Page 72 of 31,764
Β« previous page Β» next page
Filters