7.1

CVSS3.1

CVE-2025-65203 -

KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated form fields and exfiltrate credentials.

📅 Published: Dec. 17, 2025, midnight 🔄 Last Modified: Dec. 17, 2025, 9:18 p.m.

0.0

CVE-2025-67793 -

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This privilege is included by default in the Administr…

📅 Published: Dec. 17, 2025, midnight 🔄 Last Modified: Dec. 17, 2025, 9:16 p.m.

7.2

CVSS3.1

CVE-2025-67172 -

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

📅 Published: Dec. 17, 2025, midnight 🔄 Last Modified: Dec. 17, 2025, 9:18 p.m.

0.0

CVE-2025-67074 -

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serverName`) to /goform/AdvSetMacMtuWan.

📅 Published: Dec. 17, 2025, midnight 🔄 Last Modified: Dec. 18, 2025, 9:57 a.m.

6.1

CVSS3.1

CVE-2025-65233 -

Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.

📅 Published: Dec. 17, 2025, midnight 🔄 Last Modified: Dec. 17, 2025, 8:48 p.m.

0.0

CVE-2025-67790 -

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on Windows computers by using an IOCTL and an unterminated string.

📅 Published: Dec. 17, 2025, midnight 🔄 Last Modified: Dec. 17, 2025, 8:56 p.m.

7.3

CVSS3.1

CVE-2025-67285 -

A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for this issue is that attackers inject malicious code from the parameter 'id' and use it directly in SQL queries without the need for appropriate cleanin…

📅 Published: Dec. 17, 2025, midnight 🔄 Last Modified: Dec. 18, 2025, 9:57 a.m.

8.8

CVSS3.1

CVE-2025-14766 - chromium-browser: Google Chrome V8: Out-of-bounds read and write leads to heap corruption

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

📅 Published: Dec. 16, 2025, 10:54 p.m. 🔄 Last Modified: Dec. 18, 2025, 9:15 p.m.

8.8

CVSS3.1

CVE-2025-14765 - chromium-browser: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corrupt…

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

📅 Published: Dec. 16, 2025, 10:54 p.m. 🔄 Last Modified: Dec. 18, 2025, 7:53 p.m.

8.6

CVSS4.0

CVE-2025-34288 - Nagios XI Privilege Escalation via Writable PHP Include Executed with Sudo

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file that is writable by a lowe…

📅 Published: Dec. 16, 2025, 10:17 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:08 p.m.
Total resulsts: 323587
Page 80 of 32,359
« previous page » next page
Filters