8.7

CVSS4.0

CVE-2025-34452 - Streama Subtitle Download Path Traversal and SSRF Leading to Arbitrary File Write

Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow an authenticated attacker to write arbitrary files to the server filesystem. The issue exists in the subtitle download func…

📅 Published: Dec. 18, 2025, 9:30 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

6.9

CVSS4.0

CVE-2025-34451 - rofl0r/proxychains-ng <= 4.17 Stack-based Buffer Overflow

rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password f…

📅 Published: Dec. 18, 2025, 9:16 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

6.9

CVSS4.0

CVE-2025-34450 - merbanan/rtl_433 <= 25.02 Stack-based Buffer Overflow

merbanan/rtl_433 versions up to and including 25.02 and prior to commit 25e47f8 contain a stack-based buffer overflow vulnerability in the function parse_rfraw() located in src/rfraw.c. When processing crafted or excessively large raw RF input data, the application may write beyond the bounds of a …

📅 Published: Dec. 18, 2025, 9:15 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

6.9

CVSS4.0

CVE-2025-34449 - Genymobile/scrcpy <= 3.3.3 Global Buffer Overflow

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-ser…

📅 Published: Dec. 18, 2025, 9:15 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

7.5

CVSS3.1

CVE-2025-53710 - Network boundaries not respected in certain Foundry namespaces.

Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that executed user-contr…

📅 Published: Dec. 18, 2025, 9:05 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

6.3

CVSS4.0

CVE-2025-68161 - Apache Log4j Core: Missing TLS hostname verification in Socket appender

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribu…

📅 Published: Dec. 18, 2025, 8:47 p.m. 🔄 Last Modified: Jan. 20, 2026, 1:15 a.m.

5.3

CVSS4.0

CVE-2025-67653 - Advantech WebAccess/SCADA Path Traversal

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

📅 Published: Dec. 18, 2025, 8:38 p.m. 🔄 Last Modified: Dec. 31, 2025, 7:24 p.m.

7.7

CVSS4.0

CVE-2025-62004 - BullWall Server Intrusion Protection (SIP) initialization race condition

BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local, authenticated attacker can log in after boot and before SIP MFA is running. The SIP services do not retroactively enforce MFA or disconnect sessions that were not subject to SIP …

📅 Published: Dec. 18, 2025, 8:36 p.m. 🔄 Last Modified: Jan. 15, 2026, 8:16 p.m.

7.7

CVSS4.0

CVE-2025-62003 - BullWall Server Intrusion Protection RDP MFA connection delay

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be…

📅 Published: Dec. 18, 2025, 8:35 p.m. 🔄 Last Modified: Jan. 15, 2026, 8:16 p.m.

5.3

CVSS4.0

CVE-2025-46268 - Advantech WebAccess/SCADA SQL Injection

Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

📅 Published: Dec. 18, 2025, 8:35 p.m. 🔄 Last Modified: Dec. 31, 2025, 7:38 p.m.
Total resulsts: 343054
Page 1894 of 34,306
« previous page » next page
Filters