9.1

CVSS3.1

CVE-2025-63221 -

The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system …

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:16 p.m.

6.5

CVSS3.1

CVE-2025-63878 -

Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:07 p.m.

7.5

CVSS3.1

CVE-2025-63219 -

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compr…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:04 p.m.

9.8

CVSS3.1

CVE-2025-63207 -

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 7:55 p.m.

4.6

CVSS3.1

CVE-2025-63243 -

A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25.1 (01). The sle_sSenha parameter to the loginAlterarSenha.asp file. An attacker can craft a malicious URL that, when visited by a victim, causes arbitrary JavaScript code to be ex…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:12 p.m.

6.5

CVSS3.1

CVE-2025-63214 -

An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauthorized attackers to delete and create arbitrary accounts.

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Dec. 11, 2025, 9:09 p.m.

7.5

CVSS3.1

CVE-2025-51663 -

A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based rate limit protection and failed attempt restrictions by faking X-Real-IP and X-Forwarded-For HTTP headers. This can enable attackers to perform DoS attacks or brute force share c…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 7:29 p.m.

5.4

CVSS3.1

CVE-2025-51662 -

A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inject arbitrary JavaScript code into shared text "codeboxes". The xss payload is automatically executed in the browsers o…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 7:40 p.m.

9.8

CVSS3.1

CVE-2025-63210 -

The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during the loginWithUserNa…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 7:56 p.m.

7.2

CVSS3.1

CVE-2025-63220 -

The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the fir…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 4:44 p.m.
Total resulsts: 346640
Page 2713 of 34,664
Β« previous page Β» next page
Filters