9.3

CVSS4.0

CVE-2025-64691 - AVEVA Process Optimization Code Injection

The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application server.

πŸ“… Published: Jan. 16, 2026, 12:06 a.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

10

CVSS4.0

CVE-2025-61937 - AVEVA Process Optimization Code Injection

The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of β€œtaoimr” service, potentially resulting in complete compromise of theΒ  model application server.

πŸ“… Published: Jan. 16, 2026, 12:04 a.m. πŸ”„ Last Modified: Jan. 22, 2026, 3:20 p.m.

7.2

CVSS3.1

CVE-2025-31510 -

In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-68924 -

In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 3:05 p.m.

7.8

CVSS3.1

CVE-2025-68921 -

SteelSeries Nahimic 3 1.10.7 allows Directory traversal.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 4:33 p.m.

8.1

CVSS3.1

CVE-2025-62291 - strongswan: strongSwan: Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 mes…

In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-71020 -

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 9 p.m.

6.1

CVSS3.1

CVE-2025-56451 -

Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue parameter to the seeyon/main.do endpoint.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 3:05 p.m.

4.8

CVSS3.1

CVE-2025-51602 -

mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 3:05 p.m.

2.6

CVSS3.1

CVE-2025-61873 -

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

πŸ“… Published: Jan. 16, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 3:05 p.m.
Total resulsts: 330067
Page 204 of 33,007
Β« previous page Β» next page
Filters