7.5

CVSS3.1

CVE-2025-63895 -

An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted Link Manager Protocol (LMP) packet.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 9:21 p.m.

9.8

CVSS3.1

CVE-2025-65602 -

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:15 p.m.

7.5

CVSS3.1

CVE-2025-65831 -

The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hashes, either through exploiting cloud services, performing TLS downgrade attacks on the traffic from a mobile device, or through another means, they may be able to crack the hash in…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 6:40 p.m.

4.6

CVSS3.1

CVE-2025-65825 -

The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble the device, connect over UART, and retrieve the firmware dump for analysis. Within the NVS partition they may discover the credentials of the current and previo…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 7:15 p.m.

7.5

CVSS3.1

CVE-2025-65821 -

As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows the adversary to ref…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 21, 2026, 7:09 p.m.

6.5

CVSS3.1

CVE-2025-65814 -

A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 5:51 p.m.

8.1

CVSS3.1

CVE-2025-65295 -

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated …

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 7:49 p.m.

7.3

CVSS3.1

CVE-2025-65292 -

Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 7:55 p.m.

7.5

CVSS3.1

CVE-2025-56430 -

Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.

7.4

CVSS3.1

CVE-2025-65290 -

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 7:55 p.m.
Total resulsts: 345150
Page 2294 of 34,515
Β« previous page Β» next page
Filters