5.5

CVSS3.1

CVE-2025-67825 -

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 5:16 p.m.

6.5

CVSS3.1

CVE-2025-67091 -

An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when triggered via the LuCI web interface or authenticated API calls…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 9:28 p.m.

5.1

CVSS3.1

CVE-2025-67090 -

The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authentication endpoint (`/cgi-bin/luci`). An unauthenticated attacker on the local net…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 9:28 p.m.

6.8

CVSS3.1

CVE-2025-65731 -

An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root terminal access on a serial interface without proper access control.

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 1:07 a.m.

9.1

CVSS3.1

CVE-2025-61546 -

There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69) that enables remote attacker to create financial discrepancies by purchasing items with a negative quantity. This vulnerability is possible d…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 3:46 p.m.

7.5

CVSS3.1

CVE-2025-56424 -

An issue in Insiders Technologies GmbH e-invoice pro before release 1 Service Pack 2 allows a remote attacker to cause a denial of service via a crafted script

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 5:15 p.m.

9.8

CVSS3.1

CVE-2025-61246 -

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 9:31 p.m.

8.4

CVSS3.1

CVE-2025-68716 -

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no password, and administrators cannot disable SSH or enforce authentication via the CLI or web GUI. This allows any LAN-adjacent attacker to triviall…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 4:49 p.m.

9.1

CVSS3.1

CVE-2025-56425 -

An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earlier of enaio 11.0, and in the AppConnctor component version 11.10.0.183 and earlier of enaio 11.10. The vulnerability allows authenticated r…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 2:15 a.m.

5.4

CVSS3.1

CVE-2025-68718 -

KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root credentials (root:12345678). The administrator cannot disable these services or change the hardcoded password. (Changing the management GUI password does not affect SSH/TELNET authenti…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 4:28 p.m.
Total resulsts: 348389
Page 2159 of 34,839
Β« previous page Β» next page
Filters