Common Vulnerabilities and Exposures (CVE)

CVE-2025-2155

Dec 24, 2025 16:22:27 UTC

Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion.This issue affects Specto CM: before 17032025.

CVE-2025-43875

Dec 24, 2025 16:21:31 UTC

Under certain circumstances a successful exploitation could result in access to the device.

CVE-2025-43876

Dec 24, 2025 16:20:55 UTC

Under certain circumstances a successful exploitation could result in access to the device.

CVE-2025-13715

Dec 24, 2025 16:12:54 UTC

Tencent FaceDetection-DSFD resnet Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent FaceDetection-DSFD. User inte...

CVE-2025-13698

Dec 24, 2025 16:11:29 UTC

Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Deciso OPNsense. Authentication ...

CVE-2025-13699

Dec 24, 2025 16:10:43 UTC

MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is re...

CVE-2025-61258

Dec 24, 2025 16:06:47 UTC

Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates that they are unable to reproduce this.

CVE-2025-12838

Dec 24, 2025 16:06:22 UTC

MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSP360 Free Backup. An attacker must first obtain the ability to execu...

CVE-2025-12495

Dec 24, 2025 16:05:06 UTC

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundati...

CVE-2025-12839

Dec 24, 2025 16:04:35 UTC

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundati...

CVE-2025-12840

Dec 24, 2025 16:04:03 UTC

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundati...

CVE-2025-66209

Dec 24, 2025 15:51:59 UTC

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with app...

CVE-2025-68750

Dec 24, 2025 15:51:03 UTC

In the Linux kernel, the following vulnerability has been resolved: usb: potential integer overflow in usbg_make_tpg() The variable tpgt in usbg_make_tpg() is defined as unsigned long and is assigned to tpgt->tport_tpgt, which is defined ...

CVE-2025-13700

Dec 24, 2025 15:50:50 UTC

DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of DreamFactory. Authentication is required to exploit this vulne...

CVE-2025-12491

Dec 24, 2025 15:38:12 UTC

Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Senstar Symphony. Authentication is not required to exploit ...