4.6

CVSS3.1

CVE-2025-63243 -

A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25.1 (01). The sle_sSenha parameter to the loginAlterarSenha.asp file. An attacker can craft a malicious URL that, when visited by a victim, causes arbitrary JavaScript code to be ex…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:12 p.m.

10

CVSS3.1

CVE-2025-63224 -

The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the p…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 7:46 p.m.

9.8

CVSS3.1

CVE-2025-63223 -

The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and m…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 7:38 p.m.

9.1

CVSS3.1

CVE-2025-63221 -

The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system …

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:16 p.m.

7.2

CVSS3.1

CVE-2025-63220 -

The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the fir…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 4:44 p.m.

7.5

CVSS3.1

CVE-2025-63219 -

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compr…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:04 p.m.

9.8

CVSS3.1

CVE-2025-63218 -

The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:01 p.m.

6.5

CVSS3.1

CVE-2025-63214 -

An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauthorized attackers to delete and create arbitrary accounts.

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Dec. 11, 2025, 9:09 p.m.

9.8

CVSS3.1

CVE-2025-63213 -

The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the /cgi-bin/net_ping.cgi endpoint. An attacker can exploit this vulnerability by sending a specially crafted GET request with a malicious parameter to i…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 6:49 p.m.

6.5

CVSS3.1

CVE-2025-63212 -

GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log file located at /log/Flexiva%20LX.log. An unauthenticated attacker can retrieve valid session IDs and hijack sessions w…

πŸ“… Published: Nov. 19, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 6:31 p.m.
Total resulsts: 349182
Page 2967 of 34,919
Β« previous page Β» next page
Filters