7.5

CVSS3.1

CVE-2025-68156 - Expr has Denial of Service via Unbounded Recursion in Builtin Functions

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the ev…

πŸ“… Published: Dec. 16, 2025, 6:24 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.5

CVSS3.1

CVE-2025-68155 - @vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on Developme…

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process …

πŸ“… Published: Dec. 16, 2025, 6:20 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

8.1

CVSS3.1

CVE-2025-68154 - Command Injection in fsSize() on Windows

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without saniti…

πŸ“… Published: Dec. 16, 2025, 6:18 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

8.3

CVSS4.0

CVE-2025-68150 - Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, the Instagram authentication adapter allows clients to specify a custom API URL via the `apiURL` parameter in `authData`. This enables SSRF attacks and …

πŸ“… Published: Dec. 16, 2025, 6:15 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

6.3

CVSS3.1

CVE-2025-68146 - filelock has TOCTOU race condition that allows symlink attacks during lock file creation

filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation …

πŸ“… Published: Dec. 16, 2025, 6:10 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.4

CVSS3.1

CVE-2025-46296 -

An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and downloading application logs. This vulnerability has been fully addressed in FileMaker Server 22.0.4.

πŸ“… Published: Dec. 16, 2025, 6:07 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 2:45 p.m.

9.8

CVSS3.1

CVE-2025-46295 -

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could pote…

πŸ“… Published: Dec. 16, 2025, 6:07 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 2:50 p.m.

5.3

CVSS3.1

CVE-2025-46294 -

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerab…

πŸ“… Published: Dec. 16, 2025, 6:07 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 2:44 p.m.

2.7

CVSS4.0

CVE-2025-68142 - PyMdown Extensions has ReDOS bug in Figure Capture extension

PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption extension (`pymdownx.blocks.caption`). In systems that take unchecked user content, this could cause long hanges when processing the data …

πŸ“… Published: Dec. 16, 2025, 6:06 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.8

CVSS3.1

CVE-2025-33235 -

NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a race condition. A successful exploit of this vulnerability might lead to information disclosure, data tampering, denial of service, or escalation of privileges.

πŸ“… Published: Dec. 16, 2025, 5:38 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.
Total resulsts: 323713
Page 94 of 32,372
Β« previous page Β» next page
Filters