10

CVSS3.1

CVE-2025-67108 -

eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 5:49 p.m.

0.0

CVE-2025-68338 - net: dsa: microchip: Don't free uninitialized ksz_irq

In the Linux kernel, the following vulnerability has been resolved: net: dsa: microchip: Don't free uninitialized ksz_irq If something goes wrong at setup, ksz_irq_free() can be called on uninitialized ksz_irq (for example when ksz_ptp_irq_setup() fails). It leads to freeing uninitialized IRQ num…

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2025-65410 -

A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 5:31 p.m.

9.8

CVSS3.1

CVE-2025-29228 -

Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 5:33 p.m.

9.8

CVSS3.1

CVE-2025-51511 -

Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 5:26 p.m.

9.8

CVSS3.1

CVE-2025-50526 -

Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:45 p.m.

6.5

CVSS3.1

CVE-2025-45493 -

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:13 p.m.

9.8

CVSS3.1

CVE-2025-29229 -

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 5:32 p.m.

6.1

CVSS3.1

CVE-2025-66845 -

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoint reflects the id query parameter directly into the HTML response without output encoding or sanitization, allowing execution of arbitrary JavaScript code in a victim’s browser.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:14 p.m.

8.4

CVSS3.1

CVE-2025-25364 -

A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 5:22 p.m.
Total resulsts: 349182
Page 2472 of 34,919
Β« previous page Β» next page
Filters