Common Vulnerabilities and Exposures (CVE)

CVE-2025-68945

Dec 26, 2025 18:59:29 UTC

In Gitea before 1.21.2, an anonymous user can visit a private user's project.

CVE-2025-68940

Dec 26, 2025 18:57:56 UTC

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

CVE-2025-68939

Dec 26, 2025 18:57:27 UTC

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

CVE-2025-68938

Dec 26, 2025 18:53:35 UTC

Gitea before 1.25.2 mishandles authorization for deletion of releases.

CVE-2024-44065

Dec 26, 2025 18:35:58 UTC

Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.

CVE-2025-24148

Dec 26, 2025 16:48:50 UTC

This issue was addressed with improved handling of executable types. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious JAR file may bypass Gatekeeper checks.

CVE-2025-43296

Dec 26, 2025 16:44:12 UTC

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.

CVE-2025-43348

Dec 26, 2025 16:42:24 UTC

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app may bypass Gatekeeper checks.

CVE-2025-46291

Dec 26, 2025 16:41:07 UTC

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

CVE-2025-15082

Dec 26, 2025 16:37:54 UTC

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management Interface. Performing manipulation of the argument goformId results in information disclo...

CVE-2025-15081

Dec 26, 2025 16:37:10 UTC

A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdcapi. Such manipulation of the argument ddns_name leads to command injection. The attack may be performed from remote. Th...

CVE-2025-2405

Dec 26, 2025 16:36:33 UTC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Titarus allows Cross-Site Scripting (XSS).This issue a...

CVE-2025-15073

Dec 26, 2025 16:35:30 UTC

A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the at...

CVE-2025-15074

Dec 26, 2025 16:34:54 UTC

A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /customer_details.php. Such manipulation leads to sql injection. It is possible to launch the attack...

CVE-2025-15075

Dec 26, 2025 16:34:21 UTC

A security flaw has been discovered in itsourcecode Student Management System 1.0. This issue affects some unknown processing of the file /student_p.php. Performing manipulation of the argument ID results in sql injection. The attack can be...