5.3

CVSS4.0

CVE-2025-69268 - Spectrum reflected XSS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Reflected XSS.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

๐Ÿ“… Published: Jan. 12, 2026, 3:59 a.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 6:03 p.m.

8.8

CVSS4.0

CVE-2025-69267 - Spectrum directory path traversal

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

๐Ÿ“… Published: Jan. 12, 2026, 3:53 a.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 6:03 p.m.

6.9

CVSS4.0

CVE-2026-0853 - A-Plus Video Technologies๏ฝœNVR - Sensitive Data Exposure

Certain NVR models developed by A-Plus Video Technologies has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access the debug page and obtain device status information.

๐Ÿ“… Published: Jan. 12, 2026, 3:26 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7:15 a.m.

10

CVSS3.1

CVE-2025-52694 - Execution of arbitrary SQL commands

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability. Users and administratorsโ€ฆ

๐Ÿ“… Published: Jan. 12, 2026, 2:27 a.m. ๐Ÿ”„ Last Modified: Jan. 26, 2026, 3:15 a.m.

6.9

CVSS4.0

CVE-2026-0852 - code-projects Online Music Site AdminUpdateUser.php sql injection

A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been releaseโ€ฆ

๐Ÿ“… Published: Jan. 12, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7:15 a.m.

9.9

CVSS3.1

CVE-2025-46066 -

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

๐Ÿ“… Published: Jan. 12, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 21, 2026, 10:03 p.m.

6.5

CVSS3.1

CVE-2025-66689 -

A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The vulnerability is caused by flawed logic in the is_dangerous_path() validation function that uses exact string matching against a blacklist of system diโ€ฆ

๐Ÿ“… Published: Jan. 12, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 22, 2026, 9:57 p.m.

9.8

CVSS3.1

CVE-2025-29329 -

Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.

๐Ÿ“… Published: Jan. 12, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 22, 2026, 6:46 p.m.

9.8

CVSS3.1

CVE-2025-66802 -

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.

๐Ÿ“… Published: Jan. 12, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 9, 2026, 10:52 a.m.

6.5

CVSS3.1

CVE-2025-65553 -

D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attacker within RF range can transmit continuous interference to block sensor transmissions, resulting in missed alarms and loss of security monitoring. The device lacks jamming detectโ€ฆ

๐Ÿ“… Published: Jan. 12, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 22, 2026, 10 p.m.
Total resulsts: 349182
Page 2196 of 34,919
ยซ previous page ยป next page
Filters