0.0

CVE-2025-68897 - WordPress IF AS Shortcode plugin <= 1.2 - Remote Code Execution (RCE) vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-shortcode allows Code Injection.This issue affects IF AS Shortcode: from n/a through <= 1.2.

📅 Published: Dec. 29, 2025, 3:55 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-69206 - Hemmelig has SSRF Filter bypass in Secret Request functionality

Hemmelig is a messing app with with client-side encryption and self-destructing messages. Prior to version 7.3.3, a Server-Side Request Forgery (SSRF) filter bypass vulnerability exists in the webhook URL validation of the Secret Requests feature. The application attempts to block internal/private …

📅 Published: Dec. 29, 2025, 3:55 p.m. 🔄 Last Modified: Jan. 6, 2026, 4:30 p.m.

8.1

CVSS4.0

CVE-2025-69201 - Tugtainer has RCE in Agent Command Execution Api

Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.

📅 Published: Dec. 29, 2025, 3:51 p.m. 🔄 Last Modified: Feb. 20, 2026, 4:55 p.m.

9.3

CVSS4.0

CVE-2025-15194 - D-Link DIR-600 HTTP Header hedwig.cgi stack-based overflow

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack re…

📅 Published: Dec. 29, 2025, 3:32 p.m. 🔄 Last Modified: Jan. 13, 2026, 9:11 p.m.

7.5

CVSS3.1

CVE-2025-69200 - phpMyFAQ has unauthenticated config backup download via /api/setup/backup

phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api/setup/backup` and then download the generated ZIP from a web-accessible location. The ZIP contains sensitive configurat…

📅 Published: Dec. 29, 2025, 3:24 p.m. 🔄 Last Modified: Jan. 7, 2026, 3:35 p.m.

5.4

CVSS3.1

CVE-2025-68951 - phpMyFAQ has stored XSS in admin "List of users" via display_name HTML entity decoding (html_entity…

phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML entities. When an administra…

📅 Published: Dec. 29, 2025, 3:18 p.m. 🔄 Last Modified: Jan. 7, 2026, 3:35 p.m.

9.1

CVSS3.1

CVE-2025-68929 - Frappe may be vulnerable remote code execution due to server-side template injection

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution…

📅 Published: Dec. 29, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 31, 2025, 8:02 p.m.

5.4

CVSS3.1

CVE-2025-68928 - Frappe CRM vulnerable to authenticated XSS via website field

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.

📅 Published: Dec. 29, 2025, 3:06 p.m. 🔄 Last Modified: Jan. 5, 2026, 7:33 p.m.

8.7

CVSS4.0

CVE-2025-15193 - D-Link DWR-M920 formParentControl sub_423848 buffer overflow

A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 of the file /boafrm/formParentControl. Performing manipulation of the argument submit-url results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and m…

📅 Published: Dec. 29, 2025, 3:02 p.m. 🔄 Last Modified: Dec. 30, 2025, 8:41 p.m.

5.3

CVSS4.0

CVE-2025-15192 - D-Link DWR-M920 formLtefotaUpgradeQuectel sub_415328 command injection

A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formLtefotaUpgradeQuectel. Such manipulation of the argument fota_url leads to command injection. The attack can be executed remotely. The exploit has been…

📅 Published: Dec. 29, 2025, 2:32 p.m. 🔄 Last Modified: Dec. 30, 2025, 8:41 p.m.
Total resulsts: 346087
Page 2076 of 34,609
« previous page » next page
Filters