6.5

CVSS3.1

CVE-2025-67278 -

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:29 p.m.

7.5

CVSS3.1

CVE-2025-67133 - Denial of Service via Unauthenticated BLE Connection

An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 4 p.m.

6.5

CVSS3.1

CVE-2025-60538 -

A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:39 p.m.

6.5

CVSS3.1

CVE-2025-51626 -

SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:41 p.m.

8.2

CVSS3.1

CVE-2025-67070 -

A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker to bypass the multi-factor authentication (MFA) mechanism during the password recovery process. This results in the ability to change the admin password and gain full access to th…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-70161 -

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbit…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 8:45 p.m.

6.5

CVSS3.1

CVE-2025-67811 -

Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient input validation allows remote attackers to inject arbitrary SQL commands, resulting in unauthorized database access and potential compromise of sensitive data. Fixed in v.1.47.4 an…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 7:45 p.m.

7.5

CVSS3.1

CVE-2025-56225 -

fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 2:13 a.m.

5.3

CVSS3.1

CVE-2025-67279 -

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores password hashes in MD5 format

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:32 p.m.

6.5

CVSS3.1

CVE-2026-0665 - Qemu-kvm: heap off-by-one in kvm xen physdevop_map_pirq

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 6 p.m.
Total resulsts: 349182
Page 2218 of 34,919
Β« previous page Β» next page
Filters