0.0

CVE-2025-57443 -

FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows escalated privileges…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 2:23 p.m.

0.0

CVE-2025-60661 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 4:11 p.m.

9.3

CVSS4.0

CVE-2025-61588 - risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`

RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the…

πŸ“… Published: Oct. 1, 2025, 11:30 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 11:30 p.m.

4.3

CVSS3.1

CVE-2025-61583 - TS3 Manager is vulnerable to unauthenticated reflected XSS attack due to insecure error handling

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability exists in the error handling mechanism of the login page, where malicious scripts embedded in server hostnames …

πŸ“… Published: Oct. 1, 2025, 10:27 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 10:27 p.m.

7.5

CVSS3.1

CVE-2025-61582 - Ts3 Manager: Unauthenticated Denial of Service possible through specially crafted Unicode input

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability permits an unauthenticated actor to crash the application through the submission of specially crafted Unicode input, requiri…

πŸ“… Published: Oct. 1, 2025, 10:20 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 10:20 p.m.

2.1

CVSS4.0

CVE-2025-61587 - Weblate integration with Anubis can lead to Open Redirect via redir parameter

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attack…

πŸ“… Published: Oct. 1, 2025, 10:01 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 10:01 p.m.

9.2

CVSS4.0

CVE-2025-59951 - Termix' official Docker image contains an authentication bypass vulnerability

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix versions 1.5.0 and below, due to being configured with an Nginx reverse proxy, causes the backend to retrieve the proxy's IP instead of the client's IP…

πŸ“… Published: Oct. 1, 2025, 9:52 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 9:52 p.m.

6.1

CVSS4.0

CVE-2025-54811 - OpenPLC_V3

OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value. This leads to a crash when the server loop ends and execution hits an illegal ud2 instruction. This issue can be triggered remotely without authentication by starting the same server multiple ti…

πŸ“… Published: Oct. 1, 2025, 9:22 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 9:22 p.m.

7.8

CVSS3.1

CVE-2025-23297 -

NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged access could modify files in the Frameview SDK directory. A successful exploit of this vulnerability might lead to escalation of privileges.

πŸ“… Published: Oct. 1, 2025, 9:19 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 9:19 p.m.

6.7

CVSS3.1

CVE-2025-23355 -

NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denial of service.

πŸ“… Published: Oct. 1, 2025, 9:19 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 9:19 p.m.
Total resulsts: 312552
Page 14 of 31,256
Β« previous page Β» next page
Filters