7.5

CVSS3.1

CVE-2025-48704 -

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

๐Ÿ“… Published: Dec. 25, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 25, 2025, 5 a.m.

5.9

CVSS3.1

CVE-2025-66378 -

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

๐Ÿ“… Published: Dec. 25, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 25, 2025, 4:57 a.m.

7.5

CVSS3.1

CVE-2025-66377 -

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.

๐Ÿ“… Published: Dec. 25, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 25, 2025, 4:58 a.m.

7.5

CVSS3.1

CVE-2025-66443 -

Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.

๐Ÿ“… Published: Dec. 25, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 25, 2025, 4:50 a.m.

7.4

CVSS3.1

CVE-2025-68922 -

OpenOps before 0.6.11 allows remote code execution in the Terraform block.

๐Ÿ“… Published: Dec. 24, 2025, 11:05 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 11:12 p.m.

6.9

CVSS4.0

CVE-2025-15073 - itsourcecode Online Frozen Foods Ordering System contact_us.php sql injection

A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and โ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 11:02 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 11:02 p.m.

8.9

CVSS3.1

CVE-2025-68920 -

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

๐Ÿ“… Published: Dec. 24, 2025, 9:47 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 9:55 p.m.

5.6

CVSS3.1

CVE-2025-68919 -

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality, integrity, and avaiโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 9:01 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 9:06 p.m.

6.4

CVSS3.1

CVE-2025-68917 -

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

๐Ÿ“… Published: Dec. 24, 2025, 8:19 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 8:38 p.m.

9.3

CVSS4.0

CVE-2025-8769 - MegaSys Computer Technologies Telenium Online Web Application Improper Input Validation

Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server.

๐Ÿ“… Published: Dec. 24, 2025, 8:14 p.m. ๐Ÿ”„ Last Modified: Dec. 24, 2025, 8:14 p.m.
Total resulsts: 324355
Page 2 of 32,436
ยซ previous page ยป next page
Filters