7.8

CVSS3.1

CVE-2025-47320 - Out-of-bounds Write in Audio

Memory corruption while processing MFC channel configuration during music playback.

πŸ“… Published: Dec. 18, 2025, 5:28 a.m. πŸ”„ Last Modified: Feb. 10, 2026, 8:16 p.m.

6.7

CVSS3.1

CVE-2025-47319 - Exposure of Sensitive System Information to an Unauthorized Control Sphere in HLOS

Information disclosure while exposing internal TA-to-TA communication APIs to HLOS

πŸ“… Published: Dec. 18, 2025, 5:28 a.m. πŸ”„ Last Modified: Jan. 28, 2026, 5:08 p.m.

7.8

CVSS3.1

CVE-2025-27063 - Use After Free in Video

Memory corruption during video playback when video session open fails with time out error.

πŸ“… Published: Dec. 18, 2025, 5:28 a.m. πŸ”„ Last Modified: Jan. 28, 2026, 5:11 p.m.

3.2

CVSS3.1

CVE-2025-68462 -

Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump files of databases.

πŸ“… Published: Dec. 18, 2025, 5:14 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-68461 - roundcubemail: Roundcube Webmail: Cross-Site Scripting (XSS) vulnerability via crafted SVG animate …

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

πŸ“… Published: Dec. 18, 2025, 5 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

7.2

CVSS3.1

CVE-2025-68460 - roundcubemail: Roundcube Webmail: Information Disclosure via HTML Style Sanitizer

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

πŸ“… Published: Dec. 18, 2025, 4:54 a.m. πŸ”„ Last Modified: Jan. 2, 2026, 4:25 p.m.

6.4

CVSS3.1

CVE-2025-12885 - Embed Any Document <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function regex bypass in all versions up to, and including, 2.7.10 due to insufficient input sanitization and output escaping. This makes i…

πŸ“… Published: Dec. 18, 2025, 1:51 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-14856 - y_project RuoYi getnames code injection

A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicl…

πŸ“… Published: Dec. 18, 2025, 1:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

4.8

CVSS4.0

CVE-2025-14841 - OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference

A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. This manipulation causes null point…

πŸ“… Published: Dec. 18, 2025, 12:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-68324 - scsi: imm: Fix use-after-free bug caused by unfinished delayed work

In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item 'imm_tq' is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands. When the IMM parallel port SCSI…

πŸ“… Published: Dec. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2539 of 34,919
Β« previous page Β» next page
Filters