CVE-2025-66205 – Frappe has the possibility of SQL Injection due to improper validations
The following table lists the changes that have been made to the CVE-2025-66205 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2024-51999 – express improperly controls modification of query properties
The following table lists the changes that have been made to the CVE-2024-51999 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-58044 – JumpServer has an Open Redirect Vulnerability
The following table lists the changes that have been made to the CVE-2025-58044 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-65838 – PublicCMS File Upload Path Traversal
The following table lists the changes that have been made to the CVE-2025-65838 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-65836 – PublicCMS SimpleAiAdminController SSRF
The following table lists the changes that have been made to the CVE-2025-65836 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-63317 – Todoist SVG XSS
The following table lists the changes that have been made to the CVE-2025-63317 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-51682 – mJobtime Client-Side Authorization Bypass
The following table lists the changes that have been made to the CVE-2025-51682 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-51683 – mJobtime Blind SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-51683 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-12756 – Insecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment Deletion
The following table lists the changes that have been made to the CVE-2025-12756 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Dec. 01, 2025 Action […]
CVE-2025-55749 – The XWiki Jetty package (XJetty) allows accessing any application file through URL
XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder. It allows accessing files which might contains credentials. Fixed in 16.10.11, 17.4.4, and 17.7.0.