6.5

CVSS3.1

CVE-2025-60458 -

UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 9:58 p.m.

7.5

CVSS3.1

CVE-2025-66877 -

Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 2:26 a.m.

7.5

CVSS3.1

CVE-2025-66869 -

Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 2:24 a.m.

7.5

CVSS3.1

CVE-2025-66862 - binutils: heap-based buffer over-read in gnu_special() in cplus-dem.c

A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 7:36 p.m.

6.1

CVSS3.1

CVE-2025-57462 -

Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file.

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 8:13 p.m.

9.8

CVSS3.1

CVE-2024-25182 -

givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:23 a.m.

9.8

CVSS3.1

CVE-2024-27480 -

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:23 a.m.

6.1

CVSS3.1

CVE-2025-65442 -

DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrary JavaScript code or disclose sensitive information (e.g., user session cookies) via a crafted "wvstest" parameter in the URL or malicious script injection into window.localStorag…

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 8:07 p.m.

9.8

CVSS3.1

CVE-2025-65570 -

A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an β€œinstanceof” expression uses an array element access as the left-hand operand inside a for-in loop, the instructions implementation leaves an additional array reference on the stack rather th…

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 8:04 p.m.

8.8

CVSS3.1

CVE-2025-69194 - Wget2: arbitrary file write via metalink path traversal in gnu wget2

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or pot…

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: March 5, 2026, 8:09 p.m.
Total resulsts: 344690
Page 1944 of 34,469
Β« previous page Β» next page
Filters