4.3

CVSS3.1

CVE-2025-64056 -

File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:18 a.m.

9.6

CVSS3.1

CVE-2025-64054 -

A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:17 a.m.

5.6

CVSS3.1

CVE-2025-14087 - Glib: glib: buffer underflow in gvariant parser leads to heap corruption

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 3:30 p.m.

2.7

CVSS3.1

CVE-2025-14083 - Keycloak-server: keycloak: improper access control in admin rest api leads to information disclosure

A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS3.1

CVE-2025-64052 -

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 1:10 a.m.

8.1

CVSS3.1

CVE-2025-65879 -

Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH and passed to File.delete() without validation. A remote authen…

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 12:51 p.m.

8.8

CVSS3.1

CVE-2025-65730 -

Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for authentication.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Dec. 11, 2025, 6:01 p.m.

8.3

CVSS3.1

CVE-2025-64057 -

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:18 a.m.

4.7

CVSS3.1

CVE-2025-66270 -

The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-32899 - kde-connect: KDE Connect: Unpairing of devices via invalid broadcast UDP packet

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.

πŸ“… Published: Dec. 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2815 of 34,919
Β« previous page Β» next page
Filters