Common Vulnerabilities and Exposures (CVE)

CVE-2025-14696

Dec 15, 2025 01:32:06 UTC

A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The manipulati...

CVE-2025-43437

Dec 15, 2025 01:02:47 UTC

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in iOS 26.1 and iPadOS 26.1. An app may be able to fingerprint the user.

CVE-2025-14695

Dec 15, 2025 01:02:06 UTC

A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulation ...

CVE-2025-43532

Dec 15, 2025 00:59:37 UTC

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.8.3, macOS Sequoia 15.7.3. Processing malicious data may lead to unexpected app termination.

CVE-2025-43482

Dec 15, 2025 00:57:19 UTC

The issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.8.3, macOS Sequoia 15.7.3. An app may be able to cause a denial-of-service.

CVE-2025-14694

Dec 15, 2025 00:32:06 UTC

A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/postil/readAllPostil. Performing manipulation of the argument keyWord results in sql injection. The attack can be initiated...

CVE-2025-14693

Dec 15, 2025 00:02:06 UTC

A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads to symlink following. The attack can be executed directly on the physical device. The explo...

CVE-2025-67901

Dec 14, 2025 23:57:33 UTC

openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, allows a client to cause a server SIGSEGV by specifying a length of zero for block data, because the relationship between p->rem and p->len is not checked.

CVE-2025-14692

Dec 14, 2025 23:32:09 UTC

A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authentication/. This manipulation causes open redirect. It is possible to initiate the attack remotely. The exploit has been publish...

CVE-2025-14691

Dec 14, 2025 23:02:08 UTC

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now...

CVE-2025-67900

Dec 14, 2025 22:53:40 UTC

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

CVE-2025-67899

Dec 14, 2025 22:21:22 UTC

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

CVE-2025-67898

Dec 14, 2025 22:11:55 UTC

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

CVE-2025-13281

Dec 14, 2025 22:05:27 UTC

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoint...

CVE-2025-14674

Dec 14, 2025 18:02:14 UTC

A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/str...