6.3

CVSS4.0

CVE-2025-15108 - PandaXGO PandaX JWT Secret config.yml hard-coded key

A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5. This affects an unknown function of the file config.yml of the component JWT Secret Handler. The manipulation of the argument key results in use of hard-coded cryptographic key . The attack may be perfo…

πŸ“… Published: Dec. 27, 2025, 4:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-15107 - actiontech sqle JWT Secret jwt.go hard-coded key

A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown function of the file sqle/utils/jwt.go of the component JWT Secret Handler. The manipulation of the argument JWTSecretKey leads to use of hard-coded cryptographic key . The attack is po…

πŸ“… Published: Dec. 27, 2025, 12:32 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 10:38 p.m.

5.3

CVSS4.0

CVE-2025-15106 - getmaxun Authentication Endpoint auth.ts router.get improper authorization

A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the file server/src/routes/auth.ts of the component Authentication Endpoint. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The exploit …

πŸ“… Published: Dec. 27, 2025, 10:32 a.m. πŸ”„ Last Modified: Dec. 31, 2025, 7:23 p.m.

6.3

CVSS4.0

CVE-2025-15105 - getmaxun auth.ts hard-coded key

A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxun/maxun/blob/develop/server/src/routes/auth.ts. Performing manipulation of the argument api_key results in use of hard-coded cryptographic key . Remote exploitation of the attack…

πŸ“… Published: Dec. 27, 2025, 9:02 a.m. πŸ”„ Last Modified: Dec. 31, 2025, 7:06 p.m.

7.5

CVSS3.1

CVE-2025-59946 - NanoMQ has a Use After Free vulnerability via sub info list

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform. Prior to version 0.24.2, there is a classical data racing issue about sub info list which could result in heap use after free crash. This issue has been patched in version 0.24.2.

πŸ“… Published: Dec. 27, 2025, 12:40 a.m. πŸ”„ Last Modified: Jan. 30, 2026, 9:14 p.m.

9.3

CVSS4.0

CVE-2025-68952 - 1-click Remote Code Execution (RCE) vulnerability in Eigent

Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been identified in Eigent. This vulnerability allows an attacker to execute arbitrary code on the victim's machine or server through a specific interaction (1-click). This issue has been pa…

πŸ“… Published: Dec. 27, 2025, 12:37 a.m. πŸ”„ Last Modified: Feb. 19, 2026, 3:52 p.m.

6.9

CVSS4.0

CVE-2025-68948 - SiYuan: Information Disclosure and Authentication Bypass via Hardcoded Session Secret

SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the sensitive AccessAuthCode is…

πŸ“… Published: Dec. 27, 2025, 12:21 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 7:30 p.m.

7.3

CVSS4.0

CVE-2025-68927 - Improper Neutralization of HTML Tags in a Web Page in libredesk

Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the …

πŸ“… Published: Dec. 27, 2025, 12:04 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 2:32 p.m.

10

CVSS3.1

CVE-2025-54322 -

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

πŸ“… Published: Dec. 27, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:33 p.m.

6.1

CVSS4.0

CVE-2025-68474 - ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the avrc_vendor_msg() function of the ESP-IDF BlueDroid AVRCP stack, the allocated buffer size was validated using AVRC_MIN_CMD_LEN (20 bytes). However, the actual…

πŸ“… Published: Dec. 26, 2025, 11:57 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 4 p.m.
Total resulsts: 347394
Page 2219 of 34,740
Β« previous page Β» next page
Filters