3.3

CVSS3.1

CVE-2025-66548 - Nextcloud Deck app allows to spoof file extensions by using RTLO characters

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, file extension can be spoofed by using RTLO characters, tricking users into download files with a different extension than…

📅 Published: Dec. 5, 2025, 5:26 p.m. 🔄 Last Modified: Dec. 9, 2025, 7:01 p.m.

8.6

CVSS4.0

CVE-2020-36881 - Flexsense DiskBoss 'Add Input Directory' Buffer Overflow

Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to execute arbitrary code on the system. Attackers can exploit this by pasting a specially crafted directory path into the 'Add Input Directory' field.

📅 Published: Dec. 5, 2025, 5:20 p.m. 🔄 Last Modified: Dec. 10, 2025, 3:10 p.m.

8.6

CVSS4.0

CVE-2020-36880 - Flexsense DiskBoss 'Reports and Data Directory' Buffer Overflow

Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that allows an attacker to execute arbitrary code on the system.

📅 Published: Dec. 5, 2025, 5:18 p.m. 🔄 Last Modified: April 7, 2026, 2:04 p.m.

10

CVSS4.0

CVE-2025-34256 - Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote u…

📅 Published: Dec. 5, 2025, 5:18 p.m. 🔄 Last Modified: April 20, 2026, 4:45 p.m.

5.1

CVSS4.0

CVE-2025-34265 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via rule-engines

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later rendered in rule listings o…

📅 Published: Dec. 5, 2025, 5:18 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.

4.3

CVSS3.1

CVE-2025-66553 - Nextcloud Tables app allowed users to view columns metadata information of any table

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4.

📅 Published: Dec. 5, 2025, 5:18 p.m. 🔄 Last Modified: Dec. 9, 2025, 5:03 p.m.

8.5

CVSS4.0

CVE-2020-36879 - Flexsense DiskBoss Service Unquoted Service Path Vulnerability

Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name …

📅 Published: Dec. 5, 2025, 5:18 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-34263 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/dashboards/menus

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an authenticated user adds or edits a dashboard entry, the label and path values are stored in plugin configuration data and la…

📅 Published: Dec. 5, 2025, 5:17 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.

8.7

CVSS4.0

CVE-2020-36878 - ReQuest Serious Play F3 Media Player <= 3.0.0 Directory Traversal File Disclosure

ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resource…

📅 Published: Dec. 5, 2025, 5:17 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-34266 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/addins/menus

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin configuration data and lat…

📅 Published: Dec. 5, 2025, 5:17 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.
Total resulsts: 349182
Page 2804 of 34,919
« previous page » next page
Filters