NA - CVE-2025-1716 - picklescan before 0.0.21 does not treat...
picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on...
NA - CVE-2025-25783 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.
NA - CVE-2025-25784 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.
NA - CVE-2025-25785 - JizhiCMS v2.5.4 was discovered to contain a...
JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a...
NA - CVE-2025-25790 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.
NA - CVE-2025-25791 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.