9.8

CVSS3.1

CVE-2025-63228 -

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this by sending a crafted POST request with a malicious file (e.g., a PHP webshell) to the server. The upload…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 2:44 p.m.

7.2

CVSS3.1

CVE-2025-63227 -

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This …

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 2:43 p.m.

5.7

CVSS3.1

CVE-2025-63226 -

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Feb. 13, 2026, 4:13 p.m.

7.2

CVSS3.1

CVE-2025-63215 -

The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the fi…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 9:52 p.m.

4.9

CVSS3.1

CVE-2025-61663 - Grub2: missing unregister call for normal commands may lead to use-after-free

A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the normal command is not properly unregistered when the module is unloaded. An attacker who can execute this comman…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-61662 - Grub2: missing unregister call for gettext command may lead to use-after-free

A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 4:30 p.m.

6.5

CVSS3.1

CVE-2025-63749 -

pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 5:31 p.m.

9.1

CVSS3.1

CVE-2025-56643 -

Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to access the system, even after logout. This behavior affects session integrity and may allow unauthorized access if a token …

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:06 a.m.

6.5

CVSS3.1

CVE-2025-56499 -

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:01 p.m.

4.9

CVSS3.1

CVE-2025-54771 - Grub2: use-after-free in grub_file_close()

A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub t…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2985 of 34,919
Β« previous page Β» next page
Filters