3

CVSS3.1

CVE-2025-62505 - SSRF in lobehub/lobe-chat with native web fetch module

LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. A client can supply an arbitrary urls array together with impls containing the value naive. The service p…

πŸ“… Published: Oct. 17, 2025, 6:18 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 7:15 p.m.

5.4

CVSS3.1

CVE-2025-62430 - ClipBucket v5 stored XSS via video/photo fields

ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site scripting (XSS) in multiple video and photo metadata fields. For videos the Tags field and the Genre, Actors, Producer, Executive Producer, and Director fields in Movieinfos accep…

πŸ“… Published: Oct. 17, 2025, 5:50 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 6:15 p.m.

6.7

CVSS3.1

CVE-2025-62424 - ClipBucket path traversal vulnerability in template editor allows arbitrary file read and write

ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vulnerable to path traversal. The validation of the file-loading path is inadequate, allowing authenticated administrators to read and write arbitrary fi…

πŸ“… Published: Oct. 17, 2025, 5:23 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 6:15 p.m.

8.2

CVSS4.0

CVE-2025-62419 - DataEase vulnerable to JDBC URL injection in DB2 and MongoDB data source configuration

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data source configuration handlers. In the DB2 data source handler, when the extraParams field is empty, the HOSTNAME, PORT, and DATABASE v…

πŸ“… Published: Oct. 17, 2025, 5:11 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 6:15 p.m.

8.2

CVSS4.0

CVE-2025-62420 - DataEase vulnerable to remote code execution via H2 JDBC driver bypass

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 database connection handler. The getJdbc function in H2.java checks if the jdbcUrl starts with jdbc:h2 but returns a separate jdbc field as the actual c…

πŸ“… Published: Oct. 17, 2025, 5:11 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 6:15 p.m.

5.5

CVSS4.0

CVE-2025-62421 - DataEase vulnerable to stored cross-site scripting via file upload bypass

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scripting vulnerability exists due to improper file upload validation and authentication bypass. The StaticResourceApi interface defines a route upload/{fileId} that uses a URL path pa…

πŸ“… Published: Oct. 17, 2025, 5:11 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 6:15 p.m.

8.7

CVSS4.0

CVE-2025-62422 - DataEase SQL injection vulnerability

DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerable to SQL injection. An attacker can construct a malicious tableName parameter to execute arbitrary SQL commands. This issue is fixed in ver…

πŸ“… Published: Oct. 17, 2025, 5:11 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 6:15 p.m.

5.9

CVSS3.1

CVE-2025-62171 - ImageMagick vulnerable to denial of service via integer overflow in BMP decoder on 32-bit systems

ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating t…

πŸ“… Published: Oct. 17, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 5:15 p.m.

10

CVSS3.1

CVE-2025-62168 - Squid vulnerable to information disclosure via authentication credential leakage in error handling

Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to auth…

πŸ“… Published: Oct. 17, 2025, 4:21 p.m. πŸ”„ Last Modified: Oct. 18, 2025, 3:55 a.m.

7.5

CVSS3.1

CVE-2025-59043 - OpenBao vulnerable to denial of service via malicious JSON request processing

OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than their serialized version. It is possible to craft a JSON payload to maximize the factor between serialized memory usage and dese…

πŸ“… Published: Oct. 17, 2025, 4:03 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 5:22 p.m.
Total resulsts: 314713
Page 8 of 31,472
Β« previous page Β» next page
Filters