7.5

CVSS3.1

CVE-2025-63463 -

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 5:29 p.m.

7.5

CVSS3.1

CVE-2025-63466 -

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 5:30 p.m.

7.5

CVSS3.1

CVE-2025-63468 -

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 5:30 p.m.

7.5

CVSS3.1

CVE-2025-63465 -

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 5:29 p.m.

7.5

CVSS3.1

CVE-2025-57106 -

Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data.

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 7:44 p.m.

6.3

CVSS3.1

CVE-2025-63562 -

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., ownโ€ฆ

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 7:24 p.m.

6.5

CVSS3.1

CVE-2025-63563 -

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 7:10 p.m.

7.1

CVSS3.1

CVE-2025-57107 -

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations.

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 5, 2025, 7:42 p.m.

10

CVSS3.1

CVE-2025-29270 -

Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device.

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

3.1

CVSS3.1

CVE-2025-23050 - qt: qt5: qt6: Qt missing length checks

QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.

๐Ÿ“… Published: Oct. 31, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.
Total resulsts: 317990
Page 153 of 31,799
ยซ previous page ยป next page
Filters