9.8

CVSS3.1

CVE-2025-65820 -

An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application which opens a hidden page. This page, which is not available through the normal flows of the application, contains several devices which can be added to your accou…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:03 p.m.

6.1

CVSS3.1

CVE-2025-65754 -

Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a filename.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 7:28 p.m.

6.1

CVSS3.1

CVE-2025-56429 -

Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.

7.6

CVSS3.1

CVE-2025-24857 -

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 21, 2026, 7:14 p.m.

7.5

CVSS3.1

CVE-2025-63895 -

An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted Link Manager Protocol (LMP) packet.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 9:21 p.m.

9.8

CVSS3.1

CVE-2025-65602 -

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:15 p.m.

4.6

CVSS3.1

CVE-2025-65825 -

The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble the device, connect over UART, and retrieve the firmware dump for analysis. Within the NVS partition they may discover the credentials of the current and previo…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 7:15 p.m.

7.5

CVSS3.1

CVE-2025-65821 -

As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows the adversary to ref…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 21, 2026, 7:09 p.m.

8.1

CVSS3.1

CVE-2025-65295 -

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated …

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 7:49 p.m.

7.5

CVSS3.1

CVE-2025-56430 -

Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.
Total resulsts: 349182
Page 2695 of 34,919
Β« previous page Β» next page
Filters