6.1

CVSS3.1

CVE-2025-65754 -

Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a filename.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 7:28 p.m.

6.6

CVSS3.1

CVE-2025-65293 -

Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 7:52 p.m.

7.6

CVSS3.1

CVE-2025-24857 -

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 21, 2026, 7:14 p.m.

7.4

CVSS3.1

CVE-2025-65291 -

Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 5:04 p.m.

6.5

CVSS3.1

CVE-2025-65296 -

NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 7:46 p.m.

9.8

CVSS3.1

CVE-2025-65294 -

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 7:51 p.m.

9.8

CVSS3.1

CVE-2025-65826 -

The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unauthorized access to the Wi-Fi network of the vendor. Additionally, if an attacker were located …

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 7:14 p.m.

8.8

CVSS3.1

CVE-2025-65824 -

An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy (BLE), resulting in the firmware on the device being overwritten with the attacker's code. As the device does not perform checks on upgrades…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 21, 2026, 7:06 p.m.

6.5

CVSS3.1

CVE-2025-65815 -

A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory traversal.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 9:24 p.m.

7.5

CVSS3.1

CVE-2025-65297 -

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 5:15 p.m.
Total resulsts: 345149
Page 2295 of 34,515
Β« previous page Β» next page
Filters