10

CVSS3.1

CVE-2025-63224 -

The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the pโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 15, 2026, 7:46 p.m.

4.6

CVSS3.1

CVE-2025-63243 -

A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25.1 (01). The sle_sSenha parameter to the loginAlterarSenha.asp file. An attacker can craft a malicious URL that, when visited by a victim, causes arbitrary JavaScript code to be exโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 12, 2026, 4:12 p.m.

9.8

CVSS3.1

CVE-2025-63218 -

The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, andโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 12, 2026, 4:01 p.m.

6.5

CVSS3.1

CVE-2025-63212 -

GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions wโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 15, 2026, 6:31 p.m.

7.5

CVSS3.1

CVE-2025-63371 -

Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents.

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 11, 2025, 7:13 p.m.

9.2

CVSS4.0

CVE-2025-65015 - joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrariโ€ฆ

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the ExceededSizeError exception messages are embedded with non-decoded JWT token parts and may cause Pytโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 11:07 p.m. ๐Ÿ”„ Last Modified: Jan. 15, 2026, 10:10 p.m.

5.5

CVSS3.1

CVE-2025-65093 - LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.โ€ฆ

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly into an SQL query wiโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 11:02 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 4:18 p.m.

3.7

CVSS3.1

CVE-2025-65014 - LibreNMS has Weak Password Policy

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. This vulnerability allows administrators to create accounts with extremely weโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 11:01 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 4:17 p.m.

6.2

CVSS3.1

CVE-2025-65013 - LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameterโ€ฆ

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name parameter is reflected in the HTTP response withoutโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 11:01 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 4:17 p.m.

5.1

CVSS4.0

CVE-2025-65012 - Kirby CMS has cross-site scripting (XSS) in the changes dialog

Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Chโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, 10:44 p.m. ๐Ÿ”„ Last Modified: Nov. 26, 2025, 4:25 p.m.
Total resulsts: 343054
Page 2357 of 34,306
ยซ previous page ยป next page
Filters