8.8

CVSS3.1

CVE-2025-57201 -

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 12:32 a.m.

8.8

CVSS3.1

CVE-2025-57198 -

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi endpoint. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 12:36 a.m.

5.5

CVSS3.1

CVE-2025-63402 -

An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:29 p.m.

7.8

CVSS3.1

CVE-2025-66431 -

WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage sites" with "Domains management" and "Subdomains management."

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-63401 -

Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:31 p.m.

9.1

CVSS3.1

CVE-2025-65868 -

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 7:13 p.m.

7.7

CVSS3.1

CVE-2025-65843 -

Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature. The application follows symbolic links placed inside the ~/Library/Logs/Aquarius directory and treats them as regular files. When building the support ZIP, Aquarius re…

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:34 p.m.

4.9

CVSS3.1

CVE-2025-65955 - ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMag…

πŸ“… Published: Dec. 2, 2025, 11:02 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 2:50 a.m.

5.3

CVSS3.1

CVE-2025-55181 -

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends data to a std::vector per-loop iteration. This issue leads to unbounded memory growth and eventually ca…

πŸ“… Published: Dec. 2, 2025, 10:13 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:02 p.m.

0.0

CVE-2025-13933 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12500. Reason: This candidate is a reservation duplicate of CVE-2025-12500. Notes: All CVE users should reference CVE-2025-12500 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

πŸ“… Published: Dec. 2, 2025, 9:59 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:08 p.m.
Total resulsts: 349182
Page 2843 of 34,919
Β« previous page Β» next page
Filters