6.4

CVSS3.1

CVE-2025-14443 - Ose-openshift-apiserver: openshift api server: server-side request forgery (ssrf) vulnerability in …

A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential denial-of-service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP address and network-range validation when proces…

πŸ“… Published: Dec. 10, 2025, 1:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-8110 - File overwrite in file update API in Gogs

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

πŸ“… Published: Dec. 10, 2025, 1:23 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

6.5

CVSS3.1

CVE-2024-2105 - JBL: Improper validation of ICM field in connection requests

An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.

πŸ“… Published: Dec. 10, 2025, 1:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-2104 - JBL: Improper BLE security configurations and lack of authentication on the device's GATT server

Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile app service wich could render the device unusable.

πŸ“… Published: Dec. 10, 2025, 12:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-13184 - Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root log…

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.

πŸ“… Published: Dec. 10, 2025, 12:34 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:27 p.m.

9.3

CVSS4.0

CVE-2025-13953 - Bypass in the authentication method of the GTT Sistema de InformaciΓ³n Tributario application

Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active Directory (LDAP) login method. Authentication is performed through a local WebSocket, but the web application does not properly validate the authenticity or origin of the data rec…

πŸ“… Published: Dec. 10, 2025, 11:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-41358 - Direct reference to insecure objects (IDOR) in CronosWeb from CronosWeb i2A

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the β€˜documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/A…

πŸ“… Published: Dec. 10, 2025, 11:16 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-41732 - Stack-based buffer overflow via unsafe sscanf in check_cookie()

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

πŸ“… Published: Dec. 10, 2025, 11:04 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 4:50 p.m.

9.8

CVSS3.1

CVE-2025-41730 - Stack-based buffer overflow via unsafe sscanf in check_account()

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

πŸ“… Published: Dec. 10, 2025, 11:04 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 4:50 p.m.

0.0

CVE-2025-67689 -

Not used

πŸ“… Published: Dec. 10, 2025, 10:45 a.m. πŸ”„ Last Modified: Dec. 11, 2025, 3:55 a.m.
Total resulsts: 347632
Page 2536 of 34,764
Β« previous page Β» next page
Filters