3.1

CVSS3.1

CVE-2025-23050 -

QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-57106 -

Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:44 p.m.

6.3

CVSS3.1

CVE-2025-63562 -

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., own…

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:24 p.m.

6.5

CVSS3.1

CVE-2025-63563 -

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:10 p.m.

7.1

CVSS3.1

CVE-2025-57107 -

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:42 p.m.

10

CVSS3.1

CVE-2025-29270 -

Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.8

CVSS3.1

CVE-2025-60749 -

DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-63462 -

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:29 p.m.

7.5

CVSS3.1

CVE-2025-63561 -

Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where an attacker that opens and maintains many slow or partially-completed HTTP connections can exhaust the server’s co…

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:32 p.m.

6.1

CVSS3.1

CVE-2025-61427 -

A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the userid and password parameters.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.
Total resulsts: 317886
Page 143 of 31,789
Β« previous page Β» next page
Filters