9.9

CVSS4.0

CVE-2025-66256 - Unauthenticated Arbitrary File Upload (patch_contents.php)

Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Unrestricted file upload in patch_contents.php allows uploading malicious file…

πŸ“… Published: Nov. 26, 2025, 12:41 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 5:15 p.m.

9.9

CVSS4.0

CVE-2025-66255 - Unauthenticated Arbitrary File Upload (upgrade_contents.php)

Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious firmware packages.Β  …

πŸ“… Published: Nov. 26, 2025, 12:39 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:48 p.m.

7.8

CVSS4.0

CVE-2025-66254 - Unauthenticated Arbitrary File Deletion (upgrade_contents.php)

Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deleteupgrade parameter allows unauthenticated deletion of arbitrary f…

πŸ“… Published: Nov. 26, 2025, 12:37 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:47 p.m.

9.9

CVSS4.0

CVE-2025-66253 - Unauthenticated OS Command Injection (start_upgrade.php)

Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform User input passed directly to exec() allows remote code execution via start_upgr…

πŸ“… Published: Nov. 26, 2025, 12:36 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:47 p.m.

8.4

CVSS4.0

CVE-2025-66252 - Infinite Loop Denial of Service via Failed File Deletion

Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Infinite loop when unlink() fails in status_contents.php causing DoS. Due to the…

πŸ“… Published: Nov. 26, 2025, 12:34 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:47 p.m.

7.7

CVSS4.0

CVE-2025-66251 - Unauthenticated Path Traversal with Arbitrary File Deletion

Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletehidden parameter allows path traversal deletion of arbitrary .tgz f…

πŸ“… Published: Nov. 26, 2025, 12:32 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:46 p.m.

9.2

CVSS4.0

CVE-2025-66250 - Unauthenticated Arbitrary File Upload (status_contents.php)

Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Allows unauthenticated arbitrary file upload via /var/tdf/status_contents.php.

πŸ“… Published: Nov. 26, 2025, 12:29 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 4:46 p.m.

9.8

CVSS3.1

CVE-2025-64657 - Azure Application Gateway Elevation of Privilege Vulnerability

Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: Nov. 26, 2025, 12:20 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

9.4

CVSS3.1

CVE-2025-64656 - Azure Application Gateway Elevation of Privilege Vulnerability

Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: Nov. 26, 2025, 12:20 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

3.3

CVSS3.1

CVE-2025-65681 -

An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks.

πŸ“… Published: Nov. 26, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 3:38 p.m.
Total resulsts: 349182
Page 2898 of 34,919
Β« previous page Β» next page
Filters