9.8

CVSS3.1

CVE-2025-67073 -

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 7:45 p.m.

5.3

CVSS3.1

CVE-2025-67789 -

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 7:42 p.m.

6.1

CVSS3.1

CVE-2025-65233 -

Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 2:26 p.m.

7.1

CVSS3.1

CVE-2025-65203 -

KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated form fields and exfiltrate credentials.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 2:45 p.m.

6.2

CVSS3.1

CVE-2025-67174 -

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 7:19 p.m.

9.9

CVSS3.1

CVE-2025-67781 -

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 3:55 p.m.

6.8

CVSS3.1

CVE-2025-67173 -

A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafted POST request.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 7:18 p.m.

5.3

CVSS3.1

CVE-2025-67168 -

RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 7:18 p.m.

6.6

CVSS3.1

CVE-2025-65855 -

The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attacker with brief physical access can activate Oโ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 6, 2026, 3:09 p.m.

2.8

CVSS3.1

CVE-2025-65185 -

There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an OTP code and new password then reviewing application responses.

๐Ÿ“… Published: Dec. 17, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 3:06 p.m.
Total resulsts: 345302
Page 2174 of 34,531
ยซ previous page ยป next page
Filters