8.4

CVSS4.0

CVE-2025-53524 - Fuji Electric Monitouch V-SFT-6 Out-of-bounds Write

Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

πŸ“… Published: Dec. 17, 2025, 12:19 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

9.9

CVSS3.1

CVE-2025-14700 - Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller

An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.

πŸ“… Published: Dec. 17, 2025, 12:04 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:17 p.m.

7.1

CVSS3.1

CVE-2025-14701 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Cont…

An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.

πŸ“… Published: Dec. 17, 2025, 12:04 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:22 p.m.

7.8

CVSS3.1

CVE-2025-53919 -

An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak permissions, during installation and uninstallation. A low-privileged attacker with local access could potentially exploit this, leading to elevation…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:55 p.m.

9.8

CVSS3.1

CVE-2025-67791 -

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.

6.2

CVSS3.1

CVE-2025-67174 -

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:19 p.m.

7.8

CVSS3.1

CVE-2025-53398 -

The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:58 p.m.

9.8

CVSS3.1

CVE-2022-23851 -

Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 3:17 p.m.

6.1

CVSS3.1

CVE-2025-65233 -

Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 2:26 p.m.

6.1

CVSS3.1

CVE-2025-67170 -

A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:18 p.m.
Total resulsts: 343920
Page 2033 of 34,392
Β« previous page Β» next page
Filters