7.3

CVSS3.1

CVE-2025-67644 - LangGraph SQLite Checkpoint is vulnerable to SQL Injection via metadata filter key in checkpointer …

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.0 and below are vulnerable to SQL injection through the checkpoint implementation. Checkpoint allows attackers to manipulate SQL queries through metad…

📅 Published: Dec. 10, 2025, 11:37 p.m. 🔄 Last Modified: Dec. 10, 2025, 11:37 p.m.

9.7

CVSS3.1

CVE-2025-67511 - Cybersecurity AI (CAI) vulnerable to Command Injection in run_ssh_command_with_credentials Agent to…

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection through the run_ssh_command_with_credentials() function, which is available to AI agents. Only password and comm…

📅 Published: Dec. 10, 2025, 11:18 p.m. 🔄 Last Modified: Dec. 10, 2025, 11:18 p.m.

8.2

CVSS3.1

CVE-2025-67509 - MySQLSelectTool Read-Only Bypass via SELECT INTO OUTFILE Allows Arbitrary File Write

Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SE…

📅 Published: Dec. 10, 2025, 11:05 p.m. 🔄 Last Modified: Dec. 10, 2025, 11:05 p.m.

9.4

CVSS3.1

CVE-2025-67510 - MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent con…

📅 Published: Dec. 10, 2025, 10:55 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:55 p.m.

6.9

CVSS4.0

CVE-2025-67513 - FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module R…

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local…

📅 Published: Dec. 10, 2025, 10:43 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:43 p.m.

8.4

CVSS3.1

CVE-2025-67505 - Race condition in the Okta Java SDK

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request…

📅 Published: Dec. 10, 2025, 10:19 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:19 p.m.

5.4

CVSS3.1

CVE-2025-67490 - Auth0 Next.js SDK has Improper Request Caching Lookup

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in ver…

📅 Published: Dec. 10, 2025, 10:16 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2025-66628 - ImageMagick is vulnerable to an Integer Overflow in TIM decoder leading to out of bounds read (32-b…

ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the …

📅 Published: Dec. 10, 2025, 10:04 p.m. 🔄 Last Modified: Dec. 10, 2025, 10:04 p.m.

8.7

CVSS4.0

CVE-2025-66474 - XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injecti…

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 have insufficient protection against {{/html}} injection, whic…

📅 Published: Dec. 10, 2025, 9:59 p.m. 🔄 Last Modified: Dec. 10, 2025, 9:59 p.m.

8.7

CVSS4.0

CVE-2025-66473 - XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikis

XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any limits for the number of items that can be requested in a single request at the moment. Depending on the number of page…

📅 Published: Dec. 10, 2025, 9:51 p.m. 🔄 Last Modified: Dec. 10, 2025, 9:51 p.m.
Total resulsts: 321671
Page 1 of 32,168
» next page
Filters