2

CVSS4.0

CVE-2025-68469 - ImageMagick vulnerable to heap-buffer-overflow

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.

📅 Published: Dec. 18, 2025, 3:36 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

7.3

CVSS4.0

CVE-2025-68278 - tinacms vulnerable to arbitrary code execution

Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code. tinacms version 3.1.1, @tinacms/cli …

📅 Published: Dec. 18, 2025, 3:27 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

4.8

CVSS4.0

CVE-2025-64724 - Arduino IDE for macOS has Insecure File Permissions

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the applicat…

📅 Published: Dec. 18, 2025, 3:18 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

4.8

CVSS4.0

CVE-2025-64723 - Arduino IDE for macOS has TCC Bypass via Dynamic Library Injection

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic libraries into the ap…

📅 Published: Dec. 18, 2025, 3:15 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

7.1

CVSS4.0

CVE-2025-65011 - Unauthorized Access to files in WODESYS WD-R608U router

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by directly referencing the resource in question. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version r…

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

7.1

CVSS4.0

CVE-2025-65010 - Missing authorizations for admin panel password change in WODESYS WD-R608U router

WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) is vulnerable to Broken Access Control in initial configuration wizard.cgi endpoint. Malicious attacker can change admin panel password without authorization. The vulnerability can also be exploited after the initial configuration has b…

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

7.1

CVSS4.0

CVE-2025-65009 - Insecure Password Storage in WODESYS WD-R608U router

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) admin password is stored in configuration file as plaintext and can be obtained by unauthorized user by direct references to the resource in question. The vendor was notified early about this vulnerability, but didn't respond with t…

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

9.4

CVSS4.0

CVE-2025-65008 - OS Command Injection in WODESYS WD-R608U router

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in the adm.cgi endpoint, the malicious attacker can execute system shell commands. The vendor was notified early about this vulnerability, but didn't respond with the details of vul…

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

8.7

CVSS4.0

CVE-2025-65007 - Missing Authentication for Critical Function in WODESYS WD-R608U router

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration change module in the adm.cgi endpoint, the unauthenticated attacker can execute commands including backup creation, device restart and resetting the device to factory settings. The …

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

8.5

CVSS4.0

CVE-2025-64469 - Stack-based Buffer Overflow in LVResource::DetachResource() in NI LabVIEW

There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially…

📅 Published: Dec. 18, 2025, 2:53 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.
Total resulsts: 324358
Page 108 of 32,436
« previous page » next page
Filters