8.9

CVSS4.0

CVE-2025-64164 - DataEase is vulnerable to Oracle JNDI Injection

Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, resulting in a risk of JNDI injection (Java Naming and Directory Interface injection). This issue is fixed in version 2.10.15.

πŸ“… Published: Nov. 6, 2025, 12:07 a.m. πŸ”„ Last Modified: Nov. 7, 2025, 6:06 p.m.

9.8

CVSS3.1

CVE-2025-59396 -

The default configuration of WatchGuard Firebox devices through 2025-09-10 allows administrative access via SSH on port 4118 with the readwrite password for the admin account.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 10:31 p.m.

7.5

CVSS3.1

CVE-2025-63551 -

A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management System (CMS) thru 8.1. This flaw stems from a defect in the XML parsing logic, which allows an attacker to construct a malicious XML entity that forces…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 4:15 p.m.

8.2

CVSS3.1

CVE-2025-27919 -

An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later conne…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 6:09 p.m.

6.1

CVSS3.1

CVE-2025-12789 - Rhsso: open redirect

A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter associated with the openid-connect logout protocol does not properly validate the provided URL.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 5:59 p.m.

6.8

CVSS3.1

CVE-2025-59392 -

On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

7.1

CVSS3.1

CVE-2025-63589 -

A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are not sanitized or encoded before being inserted into the generated HTML (navigation links, breadcrumbs, search form action, footer links). An attacker-controlled string placed in the…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:29 p.m.

7.5

CVSS3.1

CVE-2025-63560 -

An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:15 p.m.

8.1

CVSS3.1

CVE-2025-63307 -

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:19 p.m.

7.4

CVSS3.1

CVE-2025-12790 - Rubygem-mqtt: rubygem-mqtt hostname validation

A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 8, 2025, 4:55 a.m.
Total resulsts: 317890
Page 85 of 31,789
Β« previous page Β» next page
Filters