6.5

CVSS3.1

CVE-2025-63296 -

KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh scans mounted TF/SD cards and, if /mnt/update.nor.sh is present, copies it to /tmp/net.sh and executes it as root.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3:15 p.m.

5.4

CVSS3.1

CVE-2025-63834 -

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 8:15 p.m.

7.5

CVSS3.1

CVE-2025-63152 -

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternParameter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:07 p.m.

6.5

CVSS3.1

CVE-2025-56503 -

An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the uninstall file with a crafted binary in the installation folder. NOTE: this is disputed by the Supplier because replacing the uninsta…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-63147 -

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:16 p.m.

6.5

CVSS3.1

CVE-2025-63456 -

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:16 p.m.

6.5

CVSS3.1

CVE-2025-63397 -

Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during broadcasting/type conversion.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 6:26 p.m.

6.5

CVSS3.1

CVE-2025-63835 -

A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to de…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:16 p.m.

7.5

CVSS3.1

CVE-2025-63154 -

TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:22 p.m.

6.5

CVSS3.1

CVE-2025-60876 - busybox: From CVEorg collector

BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw …

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 6:29 p.m.
Total resulsts: 348134
Page 2991 of 34,814
Β« previous page Β» next page
Filters