7.5

CVSS3.1

CVE-2025-54563 -

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Incorrect Access Control, leading to Remote Information Disclosure.

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 8:27 p.m.

9.8

CVSS3.1

CVE-2025-63958 -

MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, internal license server configuration, and software update parameters. An unauthe…

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 5:53 p.m.

8.8

CVSS3.1

CVE-2025-63434 -

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the …

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: Nov. 28, 2025, 5:06 p.m.

6.1

CVSS3.1

CVE-2025-63498 -

alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 5:32 p.m.

4.3

CVSS3.1

CVE-2025-63435 -

Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official u…

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: Nov. 28, 2025, 5:06 p.m.

7.5

CVSS3.1

CVE-2025-65494 -

NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certificate that causes sk_GENERAL_NAME_value() to return NULL.

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 5:17 p.m.

4.6

CVSS3.1

CVE-2025-63432 -

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack …

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: Nov. 28, 2025, 5:04 p.m.

7.0

CVSS3.1

CVE-2025-40212 - nfsd: fix refcount leak in nfsd_set_fh_dentry()

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nfsd exports a "pseudo root filesystem" which is used by NFSv4 to find the various exported filesystems using LOOKUP requests from a known root filehandle. NFSv3 uses the MOUNT pro…

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-65503 -

Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects.

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: Dec. 11, 2025, 11:22 p.m.

6.5

CVSS3.1

CVE-2025-60632 -

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API.

πŸ“… Published: Nov. 24, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 4:16 p.m.
Total resulsts: 349182
Page 2923 of 34,919
Β« previous page Β» next page
Filters