NA - CVE-2025-43931 - flask-boilerplate through a170e7c allows...
flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
NA - CVE-2025-43932 - JobCenter through 7e7b0b2 allows account...
JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
NA - CVE-2025-43933 - fblog through 983bede allows account takeover...
fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
NA - CVE-2025-45479 - Insufficient security mechanisms for created...
Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content into a container.
NA - CVE-2025-48367 - Redis is an open source, in-memory database...
Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of...
NA - CVE-2025-52492 - A vulnerability has been discovered in the...
A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credentials for the Twilio API. A remote attacker who...
NA - CVE-2025-53373 - Natours is a Tour Booking API. The attacker can...
Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled server domain in the Host header when requesting the /forgetpassword...
NA - CVE-2025-53374 - Dokploy is a self-hostable Platform as a...
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed...