7.5

CVSS3.1

CVE-2025-56431 -

Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the file_get_contents() function.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.

6.8

CVSS3.1

CVE-2025-65829 -

The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only authenticated software can execute on the device. The Secure Boot process forms a chain of trust by verifying all mutable software entities involved …

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 6:56 p.m.

4.6

CVSS3.1

CVE-2025-65832 -

The mobile application insecurely handles information stored within memory. By performing a memory dump on the application after a user has logged out and terminated it, Wi-Fi credentials sent during the pairing process, JWTs used for authentication, and other sensitive details can be retrieved. As…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 2:34 p.m.

6.5

CVSS3.1

CVE-2025-65828 -

An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in a Denial of Service. These commands include: shutdown, restart, clear config. Clear config would disassociate the current device from…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 7:01 p.m.

9.8

CVSS3.1

CVE-2025-65823 -

The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unauthorized access to the Wi-Fi network of the vendor. Additiona…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 21, 2026, 7:06 p.m.

8.4

CVSS3.1

CVE-2025-65807 -

An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 6:20 p.m.

6.5

CVSS3.1

CVE-2025-65803 -

An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted PSD file.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 6:42 p.m.

7.5

CVSS3.1

CVE-2025-65512 -

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markdownify-mcp v0.0.2 and before. This vulnerability allows an attacker to bypass private IP restrictions through hostname-based bypass and HTTP redirect chains, enabling access to in…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 4:03 p.m.

5.4

CVSS3.1

CVE-2025-67502 - Taguette does not safeguard against Open Redirect

Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites after authentication. The application accepts a user-controlled next parameter and uses it directly in HTTP redirects without any…

πŸ“… Published: Dec. 9, 2025, 11:53 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:11 p.m.

9.4

CVSS4.0

CVE-2025-67501 - WeGIA is vulnerable to SQL Injection via editar_categoria endpoint parameter

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain an SQL Injection vulnerability in the /html/matPat/editar_categoria.php endpoint. The application fails to properly validate and sanitize user inputs in the id_categoria …

πŸ“… Published: Dec. 9, 2025, 11:49 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 8:12 p.m.
Total resulsts: 345149
Page 2296 of 34,515
Β« previous page Β» next page
Filters