6.9

CVSS4.0

CVE-2025-12552 - Insufficient Password Policy

Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

📅 Published: Oct. 31, 2025, 3:43 p.m. 🔄 Last Modified: Nov. 10, 2025, 2:49 p.m.

5.3

CVSS4.0

CVE-2025-12357 - International Standards Organization ISO 15118-2 Improper Restriction of Communication Channel to I…

By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable wirelessly, within clos…

📅 Published: Oct. 31, 2025, 3:33 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-64168 - Agno session state overwrites between different sessions/users

Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent or Team during run or arun calls, a race condition can occur, causing a session_state to be assigned and persisted to the incorrect session. This may…

📅 Published: Oct. 31, 2025, 2:58 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-64385 - INCORRECT SECURITY VALIDATION IN SENDING UDP FRAMES

The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the manufacturer’s software. Using the manufacturer's software, the device can be configured via UDP. Analyzing this communication, it has been observed that any aspect of the initial…

📅 Published: Oct. 31, 2025, 2:23 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-64389 - EXCHANGE OF SENSITIVE INFORMATION IN CLEAR TEXT

The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.

📅 Published: Oct. 31, 2025, 2:19 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-64388 - Denial of service through specific packets

Denial of service of the web server through specific requests to this protocol

📅 Published: Oct. 31, 2025, 2:17 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-64387 - CLICKJACKING

The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making the victim click on a button to making them enter their login c…

📅 Published: Oct. 31, 2025, 2:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-12501 -

Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-service attacks (DoS). GameMaker users who use the network_create_server() function in their projects  are urged to update and recompile immediately.

📅 Published: Oct. 31, 2025, 2:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-12460 - Stored XSS vulnerability in Afterlogic Aurora webmail

An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img HTML tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, …

📅 Published: Oct. 31, 2025, 1:53 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-12521 - Analytify Pro <= 7.0.3 - Unauthenticated Information Exposure

The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify Tag HTML details. This makes it possible for unauthenticated attackers to extract usernames from source code. While we generally do not assign CVE IDs…

📅 Published: Oct. 31, 2025, 1:48 p.m. 🔄 Last Modified: April 22, 2026, 12:45 a.m.
Total resulsts: 346569
Page 2928 of 34,657
« previous page » next page
Filters