7.1

CVSS3.1

CVE-2025-49090 -

The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 6:31 p.m.

0.0

CVE-2025-60782 -

PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability in the topics management module (topics.php). Attackers can inject malicious JavaScript payloads into the Titlefield during topic creation or updates.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 2:27 p.m.

0.0

CVE-2025-56019 -

An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without authentication. Once an unauthorized connection is established, legitimate applications are unable to connect, cau…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 5:18 p.m.

0.0

CVE-2025-61096 -

PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 2:32 p.m.

0.0

CVE-2025-59405 -

The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a cleartext DataDog API key within in its codebase. Because application binaries can be trivially decompil…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 5:05 p.m.

0.0

CVE-2025-59403 -

The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoints on port 8080 without authentication. Endpoints include b…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 5:05 p.m.

0.0

CVE-2023-28760 -

TP-Link AX1800 WiFi 6 Router (Archer AX21) devices allow unauthenticated attackers (on the LAN) to execute arbitrary code as root via the db_dir field to minidlnad. The attacker obtains the ability to modify files.db, and that can be used to reach a stack-based buffer overflow in minidlna-1.1.2/upn…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 1:20 p.m.

0.0

CVE-2025-32942 -

SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 6:55 p.m.

0.0

CVE-2025-60660 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 4:10 p.m.

9.3

CVSS4.0

CVE-2025-61588 - risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`

RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the…

πŸ“… Published: Oct. 1, 2025, 11:30 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 11:30 p.m.
Total resulsts: 312549
Page 13 of 31,255
Β« previous page Β» next page
Filters