6.5

CVSS3.1

CVE-2025-70899 -

PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage.

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 8:01 p.m.

9.8

CVSS3.1

CVE-2025-56590 -

An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute arbitrary operating system commands on the local server.

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: Feb. 12, 2026, 3:01 p.m.

7.5

CVSS3.1

CVE-2025-56589 -

A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HTML2PDF SDK thru 11.6.0. These vulnerabilities could allow an attacker to read local files on the server or make arbitrary HTTP requests to internal or…

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 8:09 p.m.

6

CVSS3.1

CVE-2025-69820 -

Directory Traversal vulnerability in Beam beta9 v.0.1.521 allows a remote attacker to obtain sensitive information via the joinCleanPath function.

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 8:33 p.m.

6.5

CVSS3.1

CVE-2025-69612 -

A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software. The "Download Template" function in the profile dashboard does not neutralize directory traversal sequences (../) in the filePath parameter, allowing authenticated users to read …

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: Feb. 3, 2026, 2:06 p.m.

9.8

CVSS3.1

CVE-2025-69764 -

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 8:39 p.m.

7.4

CVSS3.1

CVE-2025-69821 -

An issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service via the BLE connection

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 8:27 p.m.

7.5

CVSS3.1

CVE-2025-67221 - orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents

The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: Feb. 12, 2026, 3:03 p.m.

8.8

CVSS3.1

CVE-2025-66428 -

An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2025-69822 -

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 8:11 p.m.
Total resulsts: 349182
Page 2034 of 34,919
Β« previous page Β» next page
Filters