5.5

CVSS3.1

CVE-2025-40221 - media: pci: mg4b: fix uninitialized iio scan data

In the Linux kernel, the following vulnerability has been resolved: media: pci: mg4b: fix uninitialized iio scan data Fix potential leak of uninitialized stack data to userspace by ensuring that the `scan` structure is zeroed before use.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

5.7

CVSS3.1

CVE-2025-63361 -

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to render the Administrator password in plaintext.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 3:35 p.m.

7.0

CVSS3.1

CVE-2025-40230 - mm: prevent poison consumption when splitting THP

In the Linux kernel, the following vulnerability has been resolved: mm: prevent poison consumption when splitting THP When performing memory error injection on a THP (Transparent Huge Page) mapped to userspace on an x86 server, the kernel panics with the following trace. The expected behavior is…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

6.5

CVSS3.1

CVE-2025-65900 -

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all pla…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 10, 2025, 9:38 p.m.

5.3

CVSS3.1

CVE-2025-65899 -

Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different error messages for invalid users (user_not_found) versus valid users with incorrect passwords (invalid_password). This observable response discrepancy allows unauthe…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 10, 2025, 9:39 p.m.

7.6

CVSS3.1

CVE-2025-63896 -

An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Jan. 22, 2026, 3:16 p.m.

7.5

CVSS3.1

CVE-2025-57212 -

Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a crafted request.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 10:15 p.m.

4.3

CVSS3.1

CVE-2025-65806 -

The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a nested ZIP (a ZIP containing another ZIP) where the inner archive contains an executable file (e.g. webshell.php). When the application extracts the uploaded archives, the executa…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: March 11, 2026, 9:16 p.m.

4.8

CVSS3.1

CVE-2025-66373 -

Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an invalid chunked body that includes a chunk size different from the actual size of the following chunk data, under certain ci…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:58 p.m.

7.8

CVSS3.1

CVE-2025-54305 -

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 6:50 p.m.
Total resulsts: 343944
Page 2310 of 34,395
Β« previous page Β» next page
Filters