6.8

CVSS3.1

CVE-2025-56438 -

An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically proximate attackers to escalate privileges to root via supplying a crafted update.tar archive file stored on a FAT32-formatted SD card.

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Oct. 27, 2025, 10:12 p.m.

7.0

CVSS3.1

CVE-2025-40020 - can: peak_usb: fix shift-out-of-bounds issue

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix shift-out-of-bounds issue Explicitly uses a 64-bit constant when the number of bits used for its shifting is 32 (which is the case for PC CAN FD interfaces supported by this driver). [mkl: update subject, appl…

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Oct. 27, 2025, 10:12 p.m.

7.0

CVSS3.1

CVE-2025-40018 - ipvs: Defer ip_vs_ftp unregister during netns cleanup

In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns cleanup On the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp before connections with valid cp->app pointers are flushed, leading to a use-after-free. Fix this by in…

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.5

CVSS3.1

CVE-2025-60566 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 2:26 p.m.

6.1

CVSS3.1

CVE-2025-60936 -

Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 2:32 a.m.

7.5

CVSS3.1

CVE-2025-60552 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formTcpipSetup.

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 2:31 a.m.

7.5

CVSS3.1

CVE-2025-60550 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formEasySetTimezone.

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 2:32 a.m.

8.2

CVSS3.1

CVE-2025-60801 -

jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 9:06 p.m.

7.5

CVSS3.1

CVE-2025-60555 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 2:31 a.m.

7.6

CVSS3.1

CVE-2025-60731 -

PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function

πŸ“… Published: Oct. 24, 2025, midnight πŸ”„ Last Modified: Oct. 27, 2025, 10:12 p.m.
Total resulsts: 343942
Page 2772 of 34,395
Β« previous page Β» next page
Filters