1.9

CVSS3.1

CVE-2025-11964 - OOBW in utf_16le_to_utf_8_truncated() in libpcap

On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer.

πŸ“… Published: Dec. 31, 2025, 12:58 a.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

1.9

CVSS3.1

CVE-2025-11961 - OOBR and OOBW in pcap_ether_aton() in libpcap

pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the funct…

πŸ“… Published: Dec. 31, 2025, 12:56 a.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

7.8

CVSS3.1

CVE-2025-64699 -

An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which runs with SYSTEM privileges, applies a Security Descriptor to a device object with no explicitly configured DACL. This condition could allow an attacker to perform unauthorized raw d…

πŸ“… Published: Dec. 31, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:33 p.m.

7

CVSS3.1

CVE-2025-61037 -

A local privilege escalation vulnerability exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The flaw is a Time-of-Check Time-of-Use (TOCTOU) race condition in the license management logic. The regService process, which runs with SYSTEM privileges, creates a fixed directory and writes files…

πŸ“… Published: Dec. 31, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:29 p.m.

0.0

CVE-2025-59131 - WordPress WP-CalDav2ICS plugin <= 1.3.4 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in hoernerfranz WP-CalDav2ICS wp-caldav2ics allows Stored XSS.This issue affects WP-CalDav2ICS: from n/a through <= 1.3.4.

πŸ“… Published: Dec. 30, 2025, 10:55 p.m. πŸ”„ Last Modified: April 1, 2026, 5:27 p.m.

5.1

CVSS4.0

CVE-2022-50802 - ETAP Safety Manager 1.0.0.32 Unauthenticated Reflected Cross-Site Scripting via Action Parameter

ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScript. Attackers can craft specially formed requests to execute arbitrary scripts in victim browser sessions, potentially …

πŸ“… Published: Dec. 30, 2025, 10:42 p.m. πŸ”„ Last Modified: March 5, 2026, 12:02 p.m.

9.3

CVSS4.0

CVE-2025-15114 - Ksenia Security lares Home Automation 1.6 PIN Exposure Vulnerability

Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system wit…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: March 11, 2026, 8:16 p.m.

8.4

CVSS3.1

CVE-2025-15113 - Ksenia Security lares Home Automation 1.6 Remote Code Execution via MPFS Upload

Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary …

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: March 11, 2026, 8:16 p.m.

5.1

CVSS4.0

CVE-2025-15112 - Ksenia Security lares Home Automation 1.6 URL Redirection Vulnerability

Ksenia Security lares (legacy model)Β version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a sp…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: March 11, 2026, 8:16 p.m.

9.3

CVSS4.0

CVE-2025-15111 - Ksenia Security lares Home Automation 1.6 Default Credentials Vulnerability

Ksenia Security lares (legacy model)Β version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: March 11, 2026, 8:16 p.m.
Total resulsts: 343921
Page 1812 of 34,393
Β« previous page Β» next page
Filters