9.8

CVSS3.1

CVE-2025-63225 -

The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized …

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2026, 8:54 p.m.

4.9

CVSS3.1

CVE-2025-61664 - Grub2: missing unregister call for normal_exit command may lead to use-after-free

A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after t…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-63693 -

The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows low-privilege attackers to construct comment content or request parameters and ex…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 8:07 p.m.

6.1

CVSS3.1

CVE-2025-63514 -

kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 9:16 a.m.

7.3

CVSS3.1

CVE-2025-63602 -

A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0.5, renamed to IntelliBreeze.Maintenance.Service.sys) that l…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:24 a.m.

5.1

CVSS3.1

CVE-2025-63408 -

Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a server-side forgery request (SSRF), or execute OS commands.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:25 a.m.

7.2

CVSS3.1

CVE-2025-63227 -

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This …

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 2:43 p.m.

5.7

CVSS3.1

CVE-2025-63226 -

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Feb. 13, 2026, 4:13 p.m.

5.4

CVSS3.1

CVE-2025-63883 -

A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client-side JavaScript reads attacker-controlled input (for example, values derived from the URL or page fragment) and inserts it into the DOM via unsafe sinks (innerHTML/insertAdjacent…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2026, 8:42 p.m.

7.5

CVSS3.1

CVE-2025-64076 - cbor2: cbor2: Integer Underflow and Memory Leak leading to Denial of Service

Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (source/decoder.c): (1) Integer Underflow Leading to Out-of-Bounds Read (CWE-191, CWE-125): An incorrect variable reference and missing state reset in the chunk pro…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:02 a.m.
Total resulsts: 346569
Page 2724 of 34,657
Β« previous page Β» next page
Filters