0.0

CVE-2025-68860 - WordPress Mobile builder plugin <= 1.4.2 - Broken Authentication vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder mobile-builder allows Authentication Abuse.This issue affects Mobile builder: from n/a through <= 1.4.2.

📅 Published: Dec. 29, 2025, 9:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-15205 - code-projects Student File Management System download.php sql injection

A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download.php. The manipulation of the argument istore_id leads to sql injection. The attack can be initiated remotely. The exploit is publicly …

📅 Published: Dec. 29, 2025, 9:02 p.m. 🔄 Last Modified: Jan. 7, 2026, 3 p.m.

6.3

CVSS3.1

CVE-2025-69205 - In µURU, a Specially Crafted Federation Name Allows Dialplan Injection

Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and including commit 88db9a953f38a3026bcd6816d51c7f3b93c55893, an attacker can crafts a special federation name and characters treated special by asterisk can be injected into the `Dial( …

📅 Published: Dec. 29, 2025, 8:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-15204 - SohuTV CacheCloud QuartzManageController.java doQuartzList cross site scripting

A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/main/java/com/sohu/cache/web/controller/QuartzManageController.java. Executing manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The expl…

📅 Published: Dec. 29, 2025, 8:32 p.m. 🔄 Last Modified: Jan. 6, 2026, 9:35 p.m.

4.8

CVSS4.0

CVE-2025-15203 - SohuTV CacheCloud ResourceController.java index cross site scripting

A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/com/sohu/cache/web/controller/ResourceController.java. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been …

📅 Published: Dec. 29, 2025, 8:02 p.m. 🔄 Last Modified: Jan. 6, 2026, 9:36 p.m.

4.8

CVSS4.0

CVE-2025-15202 - SohuTV CacheCloud TaskController.java taskQueueList cross site scripting

A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src/main/java/com/sohu/cache/web/controller/TaskController.java. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclo…

📅 Published: Dec. 29, 2025, 7:32 p.m. 🔄 Last Modified: Jan. 6, 2026, 9:36 p.m.

6

CVSS4.0

CVE-2025-14175 - Weak Algorithm Support in SSH Server on TL-WR820N

A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromise confidentiality.

📅 Published: Dec. 29, 2025, 7:31 p.m. 🔄 Last Modified: March 8, 2026, 1:49 a.m.

6

CVSS4.0

CVE-2025-69202 - axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth tokens, axios-cache-interceptor returns incorrect cached responses, leading to authorization bypass. The cache key is generated only from the URL, ignoring…

📅 Published: Dec. 29, 2025, 7:13 p.m. 🔄 Last Modified: Jan. 5, 2026, 8:05 p.m.

6.5

CVSS3.1

CVE-2025-68431 - libheif has Potential Heap Buffer Over-Read

libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or…

📅 Published: Dec. 29, 2025, 7:09 p.m. 🔄 Last Modified: Feb. 25, 2026, 2:53 p.m.

6.8

CVSS3.1

CVE-2025-14728 - Rapid7 Velociraptor Directory Traversal Vulnerability

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficie…

📅 Published: Dec. 29, 2025, 7:04 p.m. 🔄 Last Modified: Feb. 20, 2026, 7:37 p.m.
Total resulsts: 345149
Page 1980 of 34,515
« previous page » next page
Filters