9.6

CVSS3.1

CVE-2025-4665 -

WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades into insecure deserialization (PHP Object Injection). The weakness arises due to insufficient validation of user input in plugin endpoints, allowing โ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 11:54 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 11:54 p.m.

10

CVSS3.1

CVE-2025-64095 - DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files โ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:46 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 9:46 p.m.

6.4

CVSS3.1

CVE-2025-64094 - DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix for CVE-2025-48378. Tโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:44 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 9:44 p.m.

4.3

CVSS3.1

CVE-2025-62802 - DNN CKEditor Provider allows unauthenticated upload out-of-the-box

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most imโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:42 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 9:42 p.m.

5.4

CVSS4.0

CVE-2025-62801 - FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmcp install cursor. This vulnerability is fixeโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:36 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 9:36 p.m.

5.3

CVSS4.0

CVE-2025-62800 - FastMCP vulnerable to reflected XSS in client's callback page

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site scripting vulnerability in the OAuth client callback page (oauth_callback.py) where unescaped user-controlled values are inserted into the generated HTML, allowing arbitrary JavaScrโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 9:34 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 9:34 p.m.

5.4

CVSS3.1

CVE-2025-62798 - Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax

Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }} were evaluated by Vuโ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 8:58 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 8:58 p.m.

3.8

CVSS3.1

CVE-2025-62794 - GitHub Workflow Updater stored the optional Github token in plaintext

GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure "securestorage" api.โ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 8:53 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 8:53 p.m.

5.8

CVSS3.1

CVE-2025-62796 - PrivateBin persistent HTML injection in attachment filename enables redirect and defacement

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Versions 1.7.7 through 2.0.1 allow persistent HTML injection via the unsanitized attachment filename (attachment_name) when attachments are enabled. An attacker can modify attachment_name before encryption so that,โ€ฆ

๐Ÿ“… Published: Oct. 28, 2025, 8:47 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 8:47 p.m.

8.5

CVSS4.0

CVE-2025-43017 - HP ThinPro 8.1 SP8 Security Updates

HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.

๐Ÿ“… Published: Oct. 28, 2025, 8:40 p.m. ๐Ÿ”„ Last Modified: Oct. 28, 2025, 8:40 p.m.
Total resulsts: 316071
Page 1 of 31,608
ยป next page
Filters