9.9

CVSS3.1

CVE-2025-67164 -

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP file.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 5:48 p.m.

9.8

CVSS3.1

CVE-2025-67073 -

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 7:45 p.m.

7.8

CVSS3.1

CVE-2024-46060 -

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary comma…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 2:42 p.m.

7.5

CVSS3.1

CVE-2025-67171 -

Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:18 p.m.

8.8

CVSS3.1

CVE-2025-66953 -

CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interface and specifically the /system_setup.htm, /set_clock.htm, /receiver_setup.htm, /cal.htm?..., and /channel_setup.htm endpoints

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 7:47 p.m.

7.8

CVSS3.1

CVE-2024-46062 -

Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 2:37 p.m.

7.2

CVSS3.1

CVE-2025-66921 -

A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:52 p.m.

5.3

CVSS3.1

CVE-2025-67789 -

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:42 p.m.

4.3

CVSS3.1

CVE-2025-43536 - webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 7:21 p.m.

9.8

CVSS3.1

CVE-2025-67793 -

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This privilege is included by default in the Administr…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:54 p.m.
Total resulsts: 345151
Page 2158 of 34,516
Β« previous page Β» next page
Filters