5.5

CVSS3.1

CVE-2025-36889 -

In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Dec. 11, 2025, 7:35 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 5:29 p.m.

9.3

CVSS4.0

CVE-2025-14535 - UTT 进取 512W formConfigFastDirectionW strcpy buffer overflow

A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument ssid leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used…

πŸ“… Published: Dec. 11, 2025, 7:32 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 8:59 p.m.

9.3

CVSS4.0

CVE-2025-14534 - UTT 进取 512W Endpoint formNatStaticMap strcpy buffer overflow

A vulnerability was determined in UTT 进取 512W up to 3.1.7.7-171114. This impacts the function strcpy of the file /goform/formNatStaticMap of the component Endpoint. Executing manipulation of the argument NatBind can lead to buffer overflow. The attack can be launched remotely. The exploit has been …

πŸ“… Published: Dec. 11, 2025, 7:02 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 8:59 p.m.

5.3

CVSS4.0

CVE-2025-14531 - code-projects Rental Management System Log Transaction.java crlf injection

A vulnerability was found in code-projects Rental Management System 2.0. This affects an unknown function of the file Transaction.java of the component Log Handler. Performing manipulation results in crlf injection. The attack can be initiated remotely. The exploit has been made public and could be…

πŸ“… Published: Dec. 11, 2025, 6:32 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 7:02 p.m.

9.1

CVSS3.1

CVE-2025-13780 - Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)

pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin, posing a critical…

πŸ“… Published: Dec. 11, 2025, 6:30 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

7.8

CVSS3.1

CVE-2025-64669 - Windows Admin Center Elevation of Privilege Vulnerability

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

πŸ“… Published: Dec. 11, 2025, 6:06 p.m. πŸ”„ Last Modified: April 20, 2026, 3:45 p.m.

8.6

CVSS4.0

CVE-2025-14046 - Insufficient HTML Sanitization Allows User-Controlled DOM Elements to Overwrite Server-Initialized …

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shadow critical application state objects used by cert…

πŸ“… Published: Dec. 11, 2025, 5:52 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:47 p.m.

5.1

CVSS4.0

CVE-2025-14530 - SourceCodester Real Estate Property Listing App property.php unrestricted upload

A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin/property.php. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has bee…

πŸ“… Published: Dec. 11, 2025, 5:32 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 6:55 p.m.

6.9

CVSS4.0

CVE-2025-14529 - Campcodes Retro Basketball Shoes Online Store admin_running.php sql injection

A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. This manipulation of the argument pid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published an…

πŸ“… Published: Dec. 11, 2025, 5:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 5:46 a.m.

1

CVSS4.0

CVE-2025-13912 - Potential non-constant time compiled code with Clang LLVM

Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.

πŸ“… Published: Dec. 11, 2025, 5:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346555
Page 2396 of 34,656
Β« previous page Β» next page
Filters