3.7

CVSS3.1

CVE-2025-48985 -

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade. More details: https://vercel.com/changelog/cve-2025-48985-input-validatio…

πŸ“… Published: Nov. 7, 2025, 12:43 a.m. πŸ”„ Last Modified: Nov. 7, 2025, 6:35 p.m.

6.9

CVSS3.1

CVE-2025-52662 -

A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. All users are encouraged to upgrade. More details: https://vercel.com/changelog/cve-2025-52662-xss-on-nuxt-devtools

πŸ“… Published: Nov. 7, 2025, 12:43 a.m. πŸ”„ Last Modified: Nov. 7, 2025, 6:39 p.m.

5.4

CVSS3.1

CVE-2025-61261 -

A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-63717 -

The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie restrictions, allowing attacke…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.5

CVSS3.1

CVE-2025-57698 -

AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface '/plugin/install-upload' parses the filename from the request body provided by the user, and directly uses the filename to assign to file_path without checking the valid…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.

9.1

CVSS3.1

CVE-2025-63690 -

In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is possible to execute any Java class with a parameterless constructor and its methods with parameter type String through reflection. At this time, the …

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-63687 -

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:15 p.m.

0.0

CVE-2025-63640 -

Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser …

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0.0

CVE-2025-57697 -

AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image_bs64 function defined in entities.py opens the image specified by the user in the request body and returns the image content as a base64-encoded string without checking the legit…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:14 p.m.

0.0

CVE-2025-63638 -

Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clic…

πŸ“… Published: Nov. 7, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318274
Page 98 of 31,828
Β« previous page Β» next page
Filters