8.4

CVSS4.0

CVE-2025-66589 - Out-of-bounds Read vulnerability in AzeoTech DAQFactory

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash.

📅 Published: Dec. 11, 2025, 8:48 p.m. 🔄 Last Modified: Jan. 2, 2026, 8:09 p.m.

8.4

CVSS4.0

CVE-2025-66590 - Out-of-bounds Write vulnerability in AzeoTech DAQFactory

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution or a system crash.

📅 Published: Dec. 11, 2025, 8:45 p.m. 🔄 Last Modified: Jan. 2, 2026, 8:05 p.m.

5.4

CVSS4.0

CVE-2025-13663 - Quartus Prime Pro Edition Installer Advisory

Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus target installation directory if the target installation directory already exists.

📅 Published: Dec. 11, 2025, 8:35 p.m. 🔄 Last Modified: Jan. 12, 2026, 3:08 p.m.

6.9

CVSS4.0

CVE-2025-14537 - code-projects Class and Exam Timetable Management preview7.php sql injection

A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some unknown functionality of the file /preview7.php. This manipulation of the argument course_year_section/semester causes sql injection. Remote exploitation of the attack is possible…

📅 Published: Dec. 11, 2025, 8:32 p.m. 🔄 Last Modified: Dec. 16, 2025, 7:03 p.m.

6.5

CVSS3.1

CVE-2025-14293 - WP Job Portal <= 2.4.0 - Authenticated (Subscriber+) Arbitrary File Read

The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files …

📅 Published: Dec. 11, 2025, 8:22 p.m. 🔄 Last Modified: April 8, 2026, 6:24 p.m.

7.5

CVSS3.1

CVE-2025-55184 - next: React Server Components: Denial of Service via unsafe HTTP deserialization

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely…

📅 Published: Dec. 11, 2025, 8:05 p.m. 🔄 Last Modified: Dec. 15, 2025, 5:15 p.m.

5.3

CVSS3.1

CVE-2025-55183 - next: React Server Components: Source code exposure through crafted HTTP request

An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically craft…

📅 Published: Dec. 11, 2025, 8:04 p.m. 🔄 Last Modified: Jan. 7, 2026, 4:26 p.m.

6.9

CVSS4.0

CVE-2025-14536 - code-projects Class and Exam Timetable Management Login index.php sql injection

A security flaw has been discovered in code-projects Class and Exam Timetable Management 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument username/password results in sql injection. The attack may be laun…

📅 Published: Dec. 11, 2025, 8:02 p.m. 🔄 Last Modified: Dec. 16, 2025, 7:02 p.m.

7.6

CVSS3.1

CVE-2025-13214 - IBM Aspera Orchestrator SQL Injection

IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

📅 Published: Dec. 11, 2025, 7:49 p.m. 🔄 Last Modified: Dec. 15, 2025, 7:03 p.m.

8.1

CVSS3.1

CVE-2025-13148 - IBM Aspera Orchestrator Unverified Password Change

IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.

📅 Published: Dec. 11, 2025, 7:48 p.m. 🔄 Last Modified: Dec. 15, 2025, 7:06 p.m.
Total resulsts: 343996
Page 2138 of 34,400
« previous page » next page
Filters