0.0

CVE-2025-63687 -

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.

๐Ÿ“… Published: Nov. 7, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 7, 2025, 3:43 p.m.

8.7

CVSS4.0

CVE-2025-58423 - Advantech DeviceOn/iEdge Path Traversal

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.

๐Ÿ“… Published: Nov. 6, 2025, 10:31 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

8.7

CVSS4.0

CVE-2025-59171 - Advantech DeviceOn/iEdge Path Traversal

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

๐Ÿ“… Published: Nov. 6, 2025, 10:29 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

8.7

CVSS4.0

CVE-2025-62630 - Advantech DeviceOn/iEdge Path Traversal

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

๐Ÿ“… Published: Nov. 6, 2025, 10:27 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:54 a.m.

0.0

CVE-2025-11460 -

Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)

๐Ÿ“… Published: Nov. 6, 2025, 10:26 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:54 a.m.

0.0

CVE-2025-11458 -

Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Nov. 6, 2025, 10:26 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

0.0

CVE-2025-11756 -

Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Nov. 6, 2025, 10:26 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:54 a.m.

0.0

CVE-2025-12036 -

Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Nov. 6, 2025, 10:24 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:54 a.m.

5.3

CVSS4.0

CVE-2025-64302 - Advantech DeviceOn/iEdge Cross-site Scripting

Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.

๐Ÿ“… Published: Nov. 6, 2025, 10:24 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

7.1

CVSS4.0

CVE-2025-12636 - Ubia Ubox

The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of settings.

๐Ÿ“… Published: Nov. 6, 2025, 10:15 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:54 a.m.
Total resulsts: 317394
Page 13 of 31,740
ยซ previous page ยป next page
Filters