1.7

CVSS4.0

CVE-2025-64098 - FastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is e…

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OO…

πŸ“… Published: Feb. 3, 2026, 7:29 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:15 p.m.

7.2

CVSS4.0

CVE-2025-62799 - FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE)

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a heap buffer overflow exists in the Fast-DDS DATA_FRAG receive path. An un authenticated sender can transmit a single malformed RTPS D…

πŸ“… Published: Feb. 3, 2026, 7:26 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:11 p.m.

1.7

CVSS4.0

CVE-2025-62603 - FastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabled

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ParticipantGenericMessage is the DDS Security control-message container that carries not only the handshake but also on going security-control traffic after the handshake, such as…

πŸ“… Published: Feb. 3, 2026, 7:23 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:11 p.m.

4.7

CVSS3.1

CVE-2026-25616 - Blesta Input Validation XSS Vulnerability

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.

πŸ“… Published: Feb. 3, 2026, 7:21 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 a.m.

1.7

CVSS4.0

CVE-2025-62602 - FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is e…

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes a heap buffer overfl…

πŸ“… Published: Feb. 3, 2026, 7:20 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:12 p.m.

7.2

CVSS3.1

CVE-2026-25615 - Object Injection Vulnerability in Blesta Versions 3.x to 5.x Before 5.13.3

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.

πŸ“… Published: Feb. 3, 2026, 7:18 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 a.m.

7.5

CVSS3.1

CVE-2026-25614 - Object Injection in Blesta 3.x–5.x Allowing Remote Code Execution

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.

πŸ“… Published: Feb. 3, 2026, 7:16 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 a.m.

1.7

CVSS4.0

CVE-2025-62601 - FastDDS has heap buffer overflow in readString via Manipulated DATA Submessage when DDS Security is…

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes a heap buffer overfl…

πŸ“… Published: Feb. 3, 2026, 7:16 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:12 p.m.

8.2

CVSS4.0

CVE-2026-24441 - Tenda AC7 Transmits Admin Credentials Without HTTPS Protection

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material.

πŸ“… Published: Feb. 3, 2026, 7:14 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 a.m.

5.1

CVSS4.0

CVE-2026-24434 - Tenda AC7 Web Interface Lacks CSRF Protections for Admin Actions

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrato…

πŸ“… Published: Feb. 3, 2026, 7:13 p.m. πŸ”„ Last Modified: April 18, 2026, 6:45 p.m.
Total resulsts: 347821
Page 1689 of 34,783
Β« previous page Β» next page
Filters