9.8

CVSS3.1

CVE-2025-60738 -

An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute arbitrary code via the ping.php component does not perform secure filtering on IP parameters

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 6:57 p.m.

6.5

CVSS3.1

CVE-2025-60794 -

Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 3:34 p.m.

4.3

CVSS3.1

CVE-2025-65220 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 5:26 p.m.

9.8

CVSS3.1

CVE-2025-63888 -

The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 3:40 p.m.

5.5

CVSS3.1

CVE-2025-13467 - Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation

A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-65226 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 5:24 p.m.

4.3

CVSS3.1

CVE-2025-65222 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 5:25 p.m.

7.5

CVSS3.1

CVE-2025-63889 -

The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 3:41 p.m.

6.1

CVSS3.1

CVE-2025-63848 -

Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 2:11 p.m.

6.1

CVSS3.1

CVE-2025-60737 -

Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /index.php component

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 3:32 p.m.
Total resulsts: 349182
Page 2954 of 34,919
Β« previous page Β» next page
Filters