5.3

CVSS4.0

CVE-2025-14105 - TOZED ZLT M30S/ZLT M30S PRO Web proc_post denial of service

A vulnerability was determined in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. This impacts an unknown function of the file /reqproc/proc_post of the component Web Interface. Executing manipulation of the argument goformId with the input REBOOT_DEVICE can lead to denial of service. The attack can …

πŸ“… Published: Dec. 5, 2025, 9:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2025-8148 - CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT

An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.

πŸ“… Published: Dec. 5, 2025, 8:56 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 4:52 p.m.

0.0

CVE-2025-66649 -

Further research determined the issue is not a vulnerability.

πŸ“… Published: Dec. 5, 2025, 8:23 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 4:18 p.m.

7

CVSS3.1

CVE-2025-46603 -

Dell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

πŸ“… Published: Dec. 5, 2025, 7:01 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 9:18 p.m.

7.5

CVSS3.1

CVE-2025-66624 - BACnet-stack MS/TP reply matcher OOB read

BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications services. Prior to 1.5.0.rc2, The npdu_is_expected_reply function in src/bacnet/npdu.c indexes request_pdu[offset+2/3/5] and reply_pdu[offset+1/2/4] without verifying that th…

πŸ“… Published: Dec. 5, 2025, 6:36 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 6:21 p.m.

7.4

CVSS3.1

CVE-2025-66623 - Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Conne…

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.1, in some situations, Strimzi creates an incorrect Kubernetes Role which grants the Apache Kafka Connect and Apache Kafka MirrorMaker 2 operands the …

πŸ“… Published: Dec. 5, 2025, 6:31 p.m. πŸ”„ Last Modified: March 4, 2026, 8:32 p.m.

1.3

CVSS4.0

CVE-2025-66581 - Frappe LMS is Missing Server-Side Authorization in Business Logic

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side authorization logic allowed authenticated users to perform actions beyond their assigned roles across multiple features. Because the affected endpoints r…

πŸ“… Published: Dec. 5, 2025, 6:26 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 12:08 a.m.

5.3

CVSS3.1

CVE-2025-66577 - cpp-httplib Untrusted HTTP Header Handling: X-Forwarded-For/X-Real-IP Trust

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions. An attacker can supply X-Forwarded-For or X-Real-IP headers which ge…

πŸ“… Published: Dec. 5, 2025, 6:20 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 6:09 p.m.

10

CVSS3.1

CVE-2025-66570 - cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions. An attacker can inject headers named REMOTE_ADDR, REMOTE_PORT, LOCAL…

πŸ“… Published: Dec. 5, 2025, 6:18 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 3:02 p.m.

8.2

CVSS4.0

CVE-2025-66566 - yawkat LZ4 Java has a possible information leak in Java safe decompressor

yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is r…

πŸ“… Published: Dec. 5, 2025, 6:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2802 of 34,919
Β« previous page Β» next page
Filters