5.5

CVSS3.1

CVE-2025-40213 - Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN: stack-out-of-bounds in set_mesh_sync due to memcpy from badly declared on-stack flexible array. Another crash is in set_mesh_complete() dueโ€ฆ

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-64047 -

OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 2, 2025, 3:07 a.m.

6.5

CVSS3.1

CVE-2025-63914 -

An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although the contents are extracted into a temporary folder that is cleared before each extraction, successfully uploadiโ€ฆ

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 30, 2025, 5:33 p.m.

8.1

CVSS3.1

CVE-2025-60915 -

An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted request.

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 28, 2025, 4:22 p.m.

8.8

CVSS3.1

CVE-2025-56400 -

Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa accounโ€ฆ

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 30, 2025, 5:51 p.m.

9.8

CVSS3.1

CVE-2024-47856 -

In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that โ€ฆ

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 30, 2025, 5:25 p.m.

6.1

CVSS3.1

CVE-2025-64048 -

YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the ArticleAction.class.php file due to improper neutralization of user input in the article title field.

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 1, 2025, 4 p.m.

7.5

CVSS3.1

CVE-2025-65495 -

Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2d_X509() to return -1 and be misused as a malloc() size parameter.

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 1, 2025, 5:15 p.m.

7.5

CVSS3.1

CVE-2025-54338 -

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes.

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 5, 2025, 8:28 p.m.

5.3

CVSS3.1

CVE-2025-54341 -

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values.

๐Ÿ“… Published: Nov. 24, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 5, 2025, 8:28 p.m.
Total resulsts: 349182
Page 2924 of 34,919
ยซ previous page ยป next page
Filters