7.8

CVSS3.1

CVE-2025-60865 -

Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component.

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 8:39 p.m.

7.5

CVSS3.1

CVE-2025-69981 -

FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user data…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 6:16 p.m.

6.5

CVSS3.1

CVE-2025-67189 -

A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The urlKeyword parameter is not properly validated, and the function concatenates multiple user-controlled fields into a fixed-size stack buffer without performing boundary checks. A…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 2:15 p.m.

8.8

CVSS3.1

CVE-2025-65875 -

An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:24 p.m.

9.8

CVSS3.1

CVE-2025-67186 -

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /lib/cste_modules/firewall.so. The vulnerability occurs because the `url` parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, po…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 2:17 p.m.

9.8

CVSS3.1

CVE-2025-57529 -

YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validation. This allows remote unauthenticated attackers to execute arbitrary SQL commands via crafted input to the parameter. Successful exploitation could le…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 8:41 p.m.

5.4

CVSS3.1

CVE-2025-65923 -

A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then stored in the database and executed whenever the aff…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 4:50 p.m.

6.1

CVSS3.1

CVE-2025-69429 -

The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploited by attackers to leak or tamper with the internal file system. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 4:40 p.m.

4.3

CVSS3.1

CVE-2025-63372 -

Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents.

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:26 p.m.

5.5

CVSS3.1

CVE-2025-58345 -

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_certif_11ax_mode write operation, leading to …

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 9, 2026, 6:16 p.m.
Total resulsts: 347668
Page 1698 of 34,767
Β« previous page Β» next page
Filters