9.8

CVSS3.1

CVE-2025-65570 -

A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array element access as the left-hand operand inside a for-in loop, the instructions implementation leaves an additional array reference on the stack rather th…

📅 Published: Dec. 29, 2025, midnight 🔄 Last Modified: Dec. 31, 2025, 8:04 p.m.

8.8

CVSS3.1

CVE-2025-69194 - Wget2: arbitrary file write via metalink path traversal in gnu wget2

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or pot…

📅 Published: Dec. 29, 2025, midnight 🔄 Last Modified: March 5, 2026, 8:09 p.m.

7.5

CVSS3.1

CVE-2025-66865 - binutils: stack overflow in d_print_comp_inner() in cp-demangle.c

An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

📅 Published: Dec. 29, 2025, midnight 🔄 Last Modified: Jan. 14, 2026, 7:42 p.m.

7.5

CVSS3.1

CVE-2025-66863 - binutils: BinUtils: Denial of Service via crafted PE file

An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

📅 Published: Dec. 29, 2025, midnight 🔄 Last Modified: Jan. 14, 2026, 7:38 p.m.

8.6

CVSS4.0

CVE-2025-15162 - Tenda WH450 RouteStatic stack-based overflow

A vulnerability was determined in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/RouteStatic. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been public…

📅 Published: Dec. 28, 2025, 11:32 p.m. 🔄 Last Modified: Feb. 24, 2026, 7:17 a.m.

8.6

CVSS4.0

CVE-2025-15161 - Tenda WH450 PPTPUserSetting stack-based overflow

A vulnerability was found in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/PPTPUserSetting. Performing a manipulation of the argument delno results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could b…

📅 Published: Dec. 28, 2025, 11:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

8.6

CVSS4.0

CVE-2025-15160 - Tenda WH450 PPTPServer stack-based overflow

A vulnerability has been found in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/PPTPServer. Such manipulation of the argument ip1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

📅 Published: Dec. 28, 2025, 10:32 p.m. 🔄 Last Modified: Feb. 24, 2026, 6:08 a.m.

5.3

CVSS4.0

CVE-2025-15156 - omec-project UPF PFCP Session Establishment Request messages_session.go handleSessionEstablishmentR…

A flaw has been found in omec-project UPF up to 2.1.3-dev. This affects the function handleSessionEstablishmentRequest of the file /pfcpiface/pfcpiface/messages_session.go of the component PFCP Session Establishment Request Handler. This manipulation causes null pointer dereference. The attack may …

📅 Published: Dec. 28, 2025, 10:02 p.m. 🔄 Last Modified: Dec. 29, 2025, 10:33 p.m.

4.8

CVSS4.0

CVE-2025-15155 - floooh sokol sokol_gfx.h _sg_pipeline_desc_defaults stack-based overflow

A vulnerability was detected in floooh sokol up to 16cbcc864012898793cd2bc57f802499a264ea40. The impacted element is the function _sg_pipeline_desc_defaults in the library sokol_gfx.h. The manipulation results in stack-based buffer overflow. The attack requires a local approach. The exploit is now …

📅 Published: Dec. 28, 2025, 9:32 p.m. 🔄 Last Modified: Jan. 6, 2026, 8:39 p.m.

6.9

CVSS4.0

CVE-2025-15154 - PbootCMS Header handle.php get_user_ip less trusted source

A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The attack can be initiat…

📅 Published: Dec. 28, 2025, 9:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 6:08 a.m.
Total resulsts: 343921
Page 1868 of 34,393
« previous page » next page
Filters