7.5

CVSS3.1

CVE-2025-63561 -

Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where an attacker that opens and maintains many slow or partially-completed HTTP connections can exhaust the server’s co…

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:32 p.m.

6.1

CVSS3.1

CVE-2025-61427 -

A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the userid and password parameters.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-63464 -

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:29 p.m.

7.5

CVSS3.1

CVE-2025-63459 -

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:29 p.m.

7.5

CVSS3.1

CVE-2025-63469 -

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:30 p.m.

7.5

CVSS3.1

CVE-2025-63461 -

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:30 p.m.

7.5

CVSS3.1

CVE-2025-63458 -

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:28 p.m.

7.5

CVSS3.1

CVE-2025-63454 -

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:29 p.m.

9.8

CVSS3.1

CVE-2025-57108 -

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files…

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:37 p.m.

7.5

CVSS3.1

CVE-2025-8849 - Denial of Service in danny-avila/librechat

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when exc…

πŸ“… Published: Oct. 30, 2025, 11:42 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 5:14 p.m.
Total resulsts: 317867
Page 142 of 31,787
Β« previous page Β» next page
Filters