8.8

CVSS4.0

CVE-2025-0657 - ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range

A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed packets to be sent through BACnet MS/TP network causing the devices to enter a fault state. This fault state requires a manual power cycle to return the device to network visib…

πŸ“… Published: Nov. 27, 2025, 1 a.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

8.7

CVSS4.0

CVE-2025-0658 - Automated Logic and Carrier Zone Controllers malformed packets denial of service

A vulnerability in Automated Logic and Carrier's Zone ControllerΒ via BACnet protocol causes the device to crash. The device enters a fault state; after a reset, a second packet can leave it permanently unresponsive until a manual power cycle is performed.

πŸ“… Published: Nov. 27, 2025, 1 a.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

6.9

CVSS4.0

CVE-2025-66361 -

An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.

πŸ“… Published: Nov. 27, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2025-66360 -

An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. This can lead to privilege escalation.

πŸ“… Published: Nov. 27, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 7:12 p.m.

7.0

CVSS3.1

CVE-2025-13699 - MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability

MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to exploit this vulnerability but attack vectors may…

πŸ“… Published: Nov. 27, 2025, midnight πŸ”„ Last Modified: Dec. 29, 2025, 3:58 p.m.

8.5

CVSS3.1

CVE-2025-66359 -

An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scripting (XSS) vulnerability.

πŸ“… Published: Nov. 27, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 7:08 p.m.

0.0

CVE-2025-13760 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Nov. 26, 2025, 11:33 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 11:15 p.m.

3.6

CVSS3.1

CVE-2025-66040 - Spotipy has a XSS vulnerability in OAuth callback server

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's brows…

πŸ“… Published: Nov. 26, 2025, 11:14 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

7.5

CVSS3.1

CVE-2025-64344 - Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBuffer

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected wh…

πŸ“… Published: Nov. 26, 2025, 11:05 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:06 p.m.

7.5

CVSS3.1

CVE-2025-64330 - Suricata is vulnerable to a heap buffer overflow on verdict

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a single byte read heap overflow when logging the verdict in eve.alert and eve.drop records can lead to crashes. This requires t…

πŸ“… Published: Nov. 26, 2025, 11:03 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 1:30 p.m.
Total resulsts: 344676
Page 2442 of 34,468
Β« previous page Β» next page
Filters