7.5

CVSS3.1

CVE-2025-59946 - NanoMQ has a Use After Free vulnerability via sub info list

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.

πŸ“… Published: Dec. 27, 2025, 12:40 a.m. πŸ”„ Last Modified: Jan. 30, 2026, 9:14 p.m.

9.3

CVSS4.0

CVE-2025-68952 - 1-click Remote Code Execution (RCE) vulnerability in Eigent

Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been identified in Eigent. This vulnerability allows an attacker to execute arbitrary code on the victim's machine or server through a specific interaction (1-click). This issue has been pa…

πŸ“… Published: Dec. 27, 2025, 12:37 a.m. πŸ”„ Last Modified: Feb. 19, 2026, 3:52 p.m.

6.9

CVSS4.0

CVE-2025-68948 - SiYuan: Information Disclosure and Authentication Bypass via Hardcoded Session Secret

SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the sensitive AccessAuthCode is…

πŸ“… Published: Dec. 27, 2025, 12:21 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 7:30 p.m.

7.3

CVSS4.0

CVE-2025-68927 - Improper Neutralization of HTML Tags in a Web Page in libredesk

Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the …

πŸ“… Published: Dec. 27, 2025, 12:04 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 2:32 p.m.

10

CVSS3.1

CVE-2025-54322 -

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

πŸ“… Published: Dec. 27, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:33 p.m.

6.1

CVSS4.0

CVE-2025-68474 - ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the avrc_vendor_msg() function of the ESP-IDF BlueDroid AVRCP stack, the allocated buffer size was validated using AVRC_MIN_CMD_LEN (20 bytes). However, the actual…

πŸ“… Published: Dec. 26, 2025, 11:57 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 4 p.m.

0

CVSS4.0

CVE-2025-68473 - ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the ESP-IDF Bluetooth host stack (BlueDroid), the function bta_dm_sdp_result() used a fixed-size array uuid_list[32][MAX_UUID_SIZE] to store discovered service UUI…

πŸ“… Published: Dec. 26, 2025, 11:54 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 4:01 p.m.

4.3

CVSS3.1

CVE-2025-68148 - FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After

FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to 429 Retry-After for a large list of feeds on given instance, making it unusable for majority of users. This issue has been patched in versio…

πŸ“… Published: Dec. 26, 2025, 11:46 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 9:16 p.m.

2.9

CVSS4.0

CVE-2025-68932 - FreshRSS has weak cryptographic randomness in remember-me token and nonce generation

FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() and uniqid()) to generate remember-me authentication tokens and challenge-response nonces. This allows attackers to predict valid session tokens, leadi…

πŸ“… Published: Dec. 26, 2025, 11:43 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 9:12 p.m.

10

CVSS3.1

CVE-2025-66203 - StreamVault is Vulnerable to Authenticated Remote Code Execution (RCE) via ytdlpargs Configuration …

StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault application (SpiritApplication). The application allows administrators to configure yt-dlp arguments via the /admin/api/saveConfig endpoint without s…

πŸ“… Published: Dec. 26, 2025, 11:37 p.m. πŸ”„ Last Modified: March 9, 2026, 1:41 p.m.
Total resulsts: 343923
Page 1874 of 34,393
Β« previous page Β» next page
Filters