4.3

CVSS3.1

CVE-2025-12578 - Reuters Direct <= 3.0.0 - Cross-Site Request Forgery to Settings Reset

The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the the 'class-reuters-direct-settings.php' page. This makes it possible for unauthenticated attackers to reset th…

πŸ“… Published: Nov. 27, 2025, 2:26 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-66314 -

Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ElasticNet UME R32: ElasticNet_UME_R32_V16.23.20.04.

πŸ“… Published: Nov. 27, 2025, 2:08 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-5540 - ALC WebCTRL Carrier i-Vu Reflected Cross-Site Scripting

The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to compromise the client browser .

πŸ“… Published: Nov. 27, 2025, 1:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2024-5539 - ALC WebCTRL Carrier i-Vu Access Control Bypass

The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.

πŸ“… Published: Nov. 27, 2025, 1:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-0657 - ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range

A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed packets to be sent through BACnet MS/TP network causing the devices to enter a fault state. This fault state requires a manual power cycle to return the device to network visib…

πŸ“… Published: Nov. 27, 2025, 1 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-0658 - Automated Logic and Carrier Zone Controllers malformed packets denial of service

A vulnerability in Automated Logic and Carrier's Zone ControllerΒ via BACnet protocol causes the device to crash. The device enters a fault state; after a reset, a second packet can leave it permanently unresponsive until a manual power cycle is performed.

πŸ“… Published: Nov. 27, 2025, 1 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.0

CVSS3.1

CVE-2025-13699 - MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability

MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to exploit this vulnerability but attack vectors may…

πŸ“… Published: Nov. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-66361 -

An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.

πŸ“… Published: Nov. 27, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2025-66360 -

An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. This can lead to privilege escalation.

πŸ“… Published: Nov. 27, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 7:12 p.m.

8.5

CVSS3.1

CVE-2025-66359 -

An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scripting (XSS) vulnerability.

πŸ“… Published: Nov. 27, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 7:08 p.m.
Total resulsts: 344690
Page 2443 of 34,469
Β« previous page Β» next page
Filters