5.3

CVSS3.1

CVE-2025-66496 - Foxit PDF Reader 3D Annotation Out-of-Bounds Memory Access Vulnerability

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening a PDF file containing malformed or specially crafted PRC content, out-of-bounds memory access may occur, resulting in memory corruption.

πŸ“… Published: Dec. 19, 2025, 7:10 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:10 a.m.

7.8

CVSS3.1

CVE-2025-66495 - Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially all…

πŸ“… Published: Dec. 19, 2025, 7:09 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:09 a.m.

7.8

CVSS3.1

CVE-2025-66494 - Foxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution Vulnerability

A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remote attacker to execute arbitrary code.

πŸ“… Published: Dec. 19, 2025, 7:08 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:08 a.m.

7.8

CVSS3.1

CVE-2025-66493 - Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, pote…

πŸ“… Published: Dec. 19, 2025, 7:07 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:08 a.m.

8.6

CVSS4.0

CVE-2025-13008 - Session Token Disclosure in M-Files Web

An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.

πŸ“… Published: Dec. 19, 2025, 7:04 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:04 a.m.

7.2

CVSS3.1

CVE-2025-13999 - HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player 2.4.0 - 2.5.1 - Unauthenticat…

The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions from 2.4.0 up to, and including, 2.5.1 via the getIcyMetadata() function. This makes it possible for unauthenticated attackers to make web requ…

πŸ“… Published: Dec. 19, 2025, 6:48 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:48 a.m.

6.4

CVSS3.1

CVE-2025-14449 - BA Book Everything <= 1.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via babe-se…

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-form shortcode in all versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen…

πŸ“… Published: Dec. 19, 2025, 6:48 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:48 a.m.

5.3

CVSS3.1

CVE-2025-13754 - Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Au…

The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner-admin` without aut…

πŸ“… Published: Dec. 19, 2025, 6:48 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:48 a.m.

6.5

CVSS3.1

CVE-2025-66174 -

There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and run a series of commands.

πŸ“… Published: Dec. 19, 2025, 6:39 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:45 a.m.

6.2

CVSS3.1

CVE-2025-66173 -

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shel…

πŸ“… Published: Dec. 19, 2025, 6:39 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:45 a.m.
Total resulsts: 323515
Page 10 of 32,352
Β« previous page Β» next page
Filters