CVE-2025-65112Critical· 9.4▾ MidnightPubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain attacks. This issue has been patched in version 1.1.3.
pubnet < 1.1.4Upgrade past the affected range:
pubnet 1.1.4Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14567Medium· 5.3A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0
CVE-2025-14038High· 7.0EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints
CVE-2026-106511Critical· 9.8MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account wi…
CVE-2025-48608Medium· 5.5In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check
CVE-2025-9815High· 7.8A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS
CVE-2025-0108Critical· 9.1An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…