7.5

CVSS3.1

CVE-2025-63651 -

A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 19, 2026, 8:38 p.m.

5.4

CVSS3.1

CVE-2025-45160 -

A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject arbitrary HTML elements โ€ฆ

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-63653 -

An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 8:34 p.m.

9.8

CVSS3.1

CVE-2025-69929 -

An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 27, 2026, 6:16 p.m.

7.5

CVSS3.1

CVE-2025-63657 -

An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 8:33 p.m.

7.5

CVSS3.1

CVE-2025-63655 -

A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 8:34 p.m.

8.8

CVSS3.1

CVE-2025-69516 -

A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier than v1.3.1, allows low-privileged users with Report Viewer or Report Manager permissions to achieve remote command execution on the โ€ฆ

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 8:33 p.m.

7.5

CVSS3.1

CVE-2025-63658 -

A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 8:33 p.m.

7.5

CVSS3.1

CVE-2025-63652 -

A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 8:34 p.m.

7.5

CVSS3.1

CVE-2025-63649 -

An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the server.

๐Ÿ“… Published: Jan. 29, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 19, 2026, 8:42 p.m.
Total resulsts: 349182
Page 1900 of 34,919
ยซ previous page ยป next page
Filters