Skip to content

Instantly share code, notes, and snippets.

View zcxlighthouse's full-sized avatar

zcxlighthouse

View GitHub Profile
@zcxlighthouse
zcxlighthouse / CVE-2025-70060
Created March 9, 2026 06:11
CVE-2025-70060
[CVE ID]
CVE-2025-70060
[PRODUCT]
yapi
[VERSION]
v1.12.0
[PROBLEM TYPE]
Improper Neutralization of Input During Web Page Generation (CWE-79)
[DESCRIPTION]
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v1.12.0. This weakness allows attackers to inject malicious scripts into web pages, potentially leading to cross-site scripting (XSS) attacks and unauthorized access to user data.
@zcxlighthouse
zcxlighthouse / CVE-2025-70059
Created March 9, 2026 06:09
CVE-2025-70059
[CVE ID]
CVE-2025-70059
[PRODUCT]
yapi
[VERSION]
v1.12.0
[PROBLEM TYPE]
Uncontrolled Resource Consumption (CWE-400)
[DESCRIPTION]
An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0. This weakness allows attackers to trigger excessive consumption of system resources, potentially leading to a denial of service (DoS) condition.
@zcxlighthouse
zcxlighthouse / CVE-2025-70050
Created March 9, 2026 06:07
CVE-2025-70050
[CVE ID]
CVE-2025-70050
[PRODUCT]
lesspass
[VERSION]
v9.6.9
[PROBLEM TYPE]
Cleartext Storage of Sensitive Information (CWE-312)
[DESCRIPTION]
An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9. This weakness allows sensitive information to be stored in an unencrypted format, potentially leading to unauthorized access and exposure of confidential data if the storage medium is compromised.
@zcxlighthouse
zcxlighthouse / CVE-2025-70048
Created March 9, 2026 06:05
CVE-2025-70048
[CVE ID]
CVE-2025-70048
[PRODUCT]
NexusInterface
[VERSION]
v3.2.0-beta.2
[PROBLEM TYPE]
Cleartext Transmission of Sensitive Information (CWE-319)
[DESCRIPTION]
An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2. This weakness allows sensitive information to be transmitted in an unencrypted format, potentially leading to unauthorized interception and exposure of confidential data.
@zcxlighthouse
zcxlighthouse / CVE-2025-70047
Created March 9, 2026 06:03
CVE-2025-70047
[CVE ID]
CVE-2025-70047
[PRODUCT]
NexusInterface
[VERSION]
v3.2.0-beta.2
[PROBLEM TYPE]
Uncontrolled Resource Consumption (CWE-400)
[DESCRIPTION]
An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.2. This weakness allows attackers to trigger excessive consumption of system resources, potentially leading to a denial of service (DoS) condition.
@zcxlighthouse
zcxlighthouse / CVE-2025-70046
Created March 9, 2026 06:02
CVE-2025-70046
[CVE ID]
CVE-2025-70046
[PRODUCT]
oa-front-service
[VERSION]
master
[PROBLEM TYPE]
Inclusion of Functionality from Untrusted Control Sphere (CWE-829)
[DESCRIPTION]
An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master. This weakness allows the product to include functionality from an untrusted control sphere, potentially leading to the execution of malicious code or unauthorized actions.
@zcxlighthouse
zcxlighthouse / CVE-2025-70042
Created March 9, 2026 06:00
CVE-2025-70042
[CVE ID]
CVE-2025-70042
[PRODUCT]
ThermaKube
[VERSION]
master
[PROBLEM TYPE]
Server-Side Request Forgery (CWE-918)
[DESCRIPTION]
An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master. This weakness allows attackers to induce the server to make unintended requests to internal or external services, potentially leading to unauthorized access or information disclosure.
@zcxlighthouse
zcxlighthouse / CVE-2025-70040
Created March 9, 2026 05:54
CVE-2025-70040
[CVE ID]
CVE-2025-70040
[PRODUCT]
jimeng-web-mcp
[VERSION]
v2.1.2
[PROBLEM TYPE]
Insertion of Sensitive Information into Log File (CWE-532)
[DESCRIPTION]
An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This weakness allows sensitive information to be written to log files, potentially leading to unauthorized exposure of confidential data if the logs are not properly secured.
@zcxlighthouse
zcxlighthouse / CVE-2025-70039
Created March 9, 2026 05:52
CVE-2025-70039
[CVE ID]
CVE-2025-70039
[PRODUCT]
Twake
[VERSION]
v2023.Q1.1223
[PROBLEM TYPE]
Improper Neutralization of Special Elements used in an OS Command (CWE-78)
[DESCRIPTION]
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223. This weakness allows attackers to inject and execute arbitrary operating system commands, potentially leading to full system compromise.
@zcxlighthouse
zcxlighthouse / CVE-2025-70038
Created March 9, 2026 05:50
CVE-2025-70038
[CVE ID]
CVE-2025-70038
[PRODUCT]
Twake
[VERSION]
v2023.Q1.1223
[PROBLEM TYPE]
Improper Neutralization of Input During Web Page Generation (CWE-79)
[DESCRIPTION]
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This weakness allows attackers to inject malicious scripts into web pages, potentially leading to cross-site scripting (XSS) attacks and unauthorized access to user data.