7.5

CVSS3.1

CVE-2025-64775 - Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS)

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.

πŸ“… Published: Dec. 1, 2025, 4:07 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 11:30 a.m.

9

CVSS3.1

CVE-2025-8351 - Scanning a malformed file in Avast Antivirus 8.3.70.94 on MacOS may result in remote code execution

Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avast Antivirus on MacOS when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of the anitvirus engine process.This issue affects Antivirus: from 8.3.70.94 before 8.3.70.98.

πŸ“… Published: Dec. 1, 2025, 3:51 p.m. πŸ”„ Last Modified: Dec. 2, 2025, 5:16 p.m.

8.6

CVSS4.0

CVE-2025-13829 -

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshToken (10 minutes user Session) * Password hashed with bcrypt…

πŸ“… Published: Dec. 1, 2025, 3:47 p.m. πŸ”„ Last Modified: Dec. 2, 2025, 5:16 p.m.

8.1

CVSS3.1

CVE-2025-10101 - Crafted Mach-O file may allow Remote Code Execution in Avast Antivirus 15.7 on MacOS

Heap-based Buffer Overflow, Out-of-bounds Write vulnerability in Avast Antivirus on MacOS of a crafted Mach-O file may allow Local Execution of Code or Denial of Service of antivirus protection. This issue affects Antivirus: from 15.7 before 3.9.2025.

πŸ“… Published: Dec. 1, 2025, 3:32 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

5.9

CVSS3.1

CVE-2024-48894 -

A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

πŸ“… Published: Dec. 1, 2025, 3:25 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 9:10 p.m.

7.5

CVSS3.1

CVE-2024-53684 -

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.

πŸ“… Published: Dec. 1, 2025, 3:25 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 9:10 p.m.

7.3

CVSS3.1

CVE-2024-45370 -

An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System 2.6.1.0. A specially crafted database record can lead to unauthorized access. An attacker can modify a local database to trigger this vulnerability.

πŸ“… Published: Dec. 1, 2025, 3:25 p.m. πŸ”„ Last Modified: Dec. 2, 2025, 5:16 p.m.

7.2

CVSS3.1

CVE-2024-49572 -

A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an una…

πŸ“… Published: Dec. 1, 2025, 3:25 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 9:10 p.m.

8.6

CVSS3.1

CVE-2024-48882 -

A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability.

πŸ“… Published: Dec. 1, 2025, 3:25 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 9:10 p.m.

7.2

CVSS3.1

CVE-2025-20085 -

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can se…

πŸ“… Published: Dec. 1, 2025, 3:25 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 8:49 p.m.
Total resulsts: 343921
Page 2342 of 34,393
Β« previous page Β» next page
Filters