CVE-2025-69286 - RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability
CVE ID : CVE-2025-69286
Published : Dec. 31, 2025, 10:15 p.m. | 2 hours, 4 minutes ago
Description : RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens are generated using the same `URLSafeTimedSerializer` with predictable inputs, enabling an unauthorized user who obtains the shared assistant/agent URL to derive the personal API key. This grants them full control over the assistant/agent owner's account. Version 0.22.0 fixes the issue.
Severity: 8.9 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-69286
Published : Dec. 31, 2025, 10:15 p.m. | 2 hours, 4 minutes ago
Description : RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens are generated using the same `URLSafeTimedSerializer` with predictable inputs, enabling an unauthorized user who obtains the shared assistant/agent URL to derive the personal API key. This grants them full control over the assistant/agent owner's account. Version 0.22.0 fixes the issue.
Severity: 8.9 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-69288 - Titra has Remote Code Execution in Admin Functionality
CVE ID : CVE-2025-69288
Published : Dec. 31, 2025, 10:15 p.m. | 2 hours, 4 minutes ago
Description : Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-69288
Published : Dec. 31, 2025, 10:15 p.m. | 2 hours, 4 minutes ago
Description : Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67703 - Stored XSS vulnerability in ArcGIS Server.
CVE ID : CVE-2025-67703
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-67703
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67704 - Stored XSS vulnerability in ArcGIS Server.
CVE ID : CVE-2025-67704
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-67704
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67705 - Reflected XSS vulnerability in ArcGIS Server.
CVE ID : CVE-2025-67705
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-67705
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67706 - Unvalidated File Upload vulnerability in ArcGIS Server.
CVE ID : CVE-2025-67706
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files file, which allows remote attackers to upload arbitrary files.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-67706
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files file, which allows remote attackers to upload arbitrary files.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67707 - Unvalidated File Upload vulnerability in ArcGIS Server.
CVE ID : CVE-2025-67707
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files file, which allows remote attackers to upload arbitrary files.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-67707
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files file, which allows remote attackers to upload arbitrary files.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67708 - Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server.
CVE ID : CVE-2025-67708
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-67708
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67709 - There is a cross site scripting issue in ArcGIS Server.
CVE ID : CVE-2025-67709
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-67709
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67710 - Stored XSS vulnerability in ArcGIS Server
CVE ID : CVE-2025-67710
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-67710
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67711 - Reflected XSS vulnerability in ArcGIS Server.
CVE ID : CVE-2025-67711
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-67711
Published : Dec. 31, 2025, 11:15 p.m. | 1 hour, 4 minutes ago
Description : There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-69412 - KDE Messagelib SSL Validation Bypass
CVE ID : CVE-2025-69412
Published : Dec. 31, 2025, 11:20 p.m. | 59 minutes ago
Description : KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Severity: 3.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-69412
Published : Dec. 31, 2025, 11:20 p.m. | 59 minutes ago
Description : KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Severity: 3.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22155 - Apache Struts Remote Code Execution Vulnerability
CVE ID : CVE-2025-22155
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22155
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22180 - Apache HTTP Server Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-22180
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22180
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22181 - Here is the title: Apache HTTP Server Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-22181
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22181
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22182 - Apache HTTP Server Remote Code Execution
CVE ID : CVE-2025-22182
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22182
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22183 - **Apache Struts Deserialization Remote Code Execution**
CVE ID : CVE-2025-22183
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22183
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22184 - Apache Struts Command Injection
CVE ID : CVE-2025-22184
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22184
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22185 - Apache Tomcat HTTP Request Smuggling
CVE ID : CVE-2025-22185
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22185
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22186 - Apache Struts Remote Code Execution Vulnerability
CVE ID : CVE-2025-22186
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22186
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22187 - Apache Struts Cross-Site Scripting (XSS)
CVE ID : CVE-2025-22187
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22187
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...