5.1

CVSS3.1

CVE-2025-65885 -

An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia E7 (Delight v1.3), Nokia C7 (Delight v6.7), Nokia 700 (Delight v1.2), Nokia 701 (Delight v1.1), Nokia 603 (Delight v1.0), Nokia 500 (Delight v1.2)…

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:55 p.m.

9.8

CVSS3.1

CVE-2024-44065 -

Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 9:35 p.m.

6.2

CVSS3.1

CVE-2024-29720 -

An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the Sciter video rendering function.

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:59 p.m.

4.3

CVSS3.1

CVE-2025-66737 -

Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:35 p.m.

8.8

CVSS3.1

CVE-2025-66738 -

An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:45 p.m.

7.5

CVSS3.1

CVE-2025-57403 -

Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading to th…

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:47 p.m.

7.5

CVSS3.1

CVE-2025-67015 -

Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1.

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:57 p.m.

7.5

CVSS3.1

CVE-2025-67014 -

Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access an administrative endpoint.

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:43 p.m.

6.5

CVSS3.1

CVE-2025-66947 -

SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter. An attacker can trigger controlled delays using SQL SLEEP() to infer database contents. Successful exploitation may lead to full database compromise, especially w…

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:54 p.m.

6.5

CVSS3.1

CVE-2025-67013 -

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

πŸ“… Published: Dec. 26, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 4:10 p.m.
Total resulsts: 343921
Page 1879 of 34,393
Β« previous page Β» next page
Filters