7.8

CVSS3.1

CVE-2025-66476 - Vim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability

Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious executables placed in the current working directory for the current edited file. On Windows, when using cmd.exe as a shell, Vim resolves e…

πŸ“… Published: Dec. 2, 2025, 9:49 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

8.7

CVSS4.0

CVE-2025-62575 - Mirion Medical EC2 Software NMIS BioDose Incorrect Permission Assignment for Critical Resource

NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.

πŸ“… Published: Dec. 2, 2025, 9:11 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 9:03 p.m.

8.4

CVSS4.0

CVE-2025-64778 - Mirion Medical EC2 Software NMIS BioDose Use of Hard-coded Credentials

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.

πŸ“… Published: Dec. 2, 2025, 9:09 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 8:57 p.m.

8.7

CVSS4.0

CVE-2025-61940 - Mirion Medical EC2 Software NMIS BioDose Use of Client-Side Authentication

NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest versi…

πŸ“… Published: Dec. 2, 2025, 9:07 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 9:03 p.m.

8.6

CVSS4.0

CVE-2025-64298 - Mirion Medical EC2 Software NMIS BioDose Incorrect Permission Assignment for Critical Resource

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configur…

πŸ“… Published: Dec. 2, 2025, 9:05 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 9:02 p.m.

7.1

CVSS4.0

CVE-2025-64642 - Mirion Medical EC2 Software NMIS BioDose Incorrect Permission Assignment for Critical Resource

NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and libraries.

πŸ“… Published: Dec. 2, 2025, 9:03 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 8:59 p.m.

0.0

CVE-2025-13923 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Dec. 2, 2025, 8:03 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 10:19 p.m.

9.3

CVSS4.0

CVE-2025-13658 - Industrial Video & Control Longwatch has a Code Injection vulnerability

A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence of code signing and execution controls. Exploitation results in SYSTEM-level privileges.

πŸ“… Published: Dec. 2, 2025, 7:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-13510 - Iskra iHUB and iHUB Lite has a Missing Authentication for Critical Function vulnerabilitiy

The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated users to access and modify critical device settings.

πŸ“… Published: Dec. 2, 2025, 7:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-13542 - DesignThemes LMS <= 1.0.4 - Unauthenticated Privilege Escalation

The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to …

πŸ“… Published: Dec. 2, 2025, 7:27 p.m. πŸ”„ Last Modified: April 21, 2026, 1:15 a.m.
Total resulsts: 349182
Page 2844 of 34,919
Β« previous page Β» next page
Filters