7.8

CVSS3.1

CVE-2025-68921 -

SteelSeries Nahimic 3 1.10.7 allows Directory traversal.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 4:33 p.m.

8.1

CVSS3.1

CVE-2025-62291 - strongswan: strongSwan: Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 mes…

In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2025-71020 -

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 20, 2026, 5:15 p.m.

6.1

CVSS3.1

CVE-2025-56451 -

Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue parameter to the seeyon/main.do endpoint.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

6.7

CVSS3.1

CVE-2025-24531 - pam_pkcs11: authentication bypass in error situations

In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

4.8

CVSS3.1

CVE-2025-51602 -

mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 20, 2026, 5:35 p.m.

4.2

CVSS3.1

CVE-2025-43904 -

In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 20, 2026, 3:29 p.m.

2.6

CVSS3.1

CVE-2025-61873 -

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.

5.5

CVSS3.1

CVE-2025-69581 -

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because proper cache-control is missing. Using the browser back button restores all personal data, allowing unauthorized users on the same device to v…

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 20, 2026, 3:20 p.m.

7.5

CVSS3.1

CVE-2025-70746 -

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.
Total resulsts: 329475
Page 148 of 32,948
Β« previous page Β» next page
Filters