6.5

CVSS3.1

CVE-2025-63384 -

A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3:25 p.m.

6.5

CVSS3.1

CVE-2025-63457 -

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:16 p.m.

7.1

CVSS3.1

CVE-2025-63711 -

A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g., superadmin_user_dele…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:16 p.m.

6.5

CVSS3.1

CVE-2025-63710 -

The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms such as tokens, nonces, or same-site cookie restrictions. An attacker can create a malicious HTML page th…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:18 p.m.

6.5

CVSS3.1

CVE-2025-63296 -

KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh scans mounted TF/SD cards and, if /mnt/update.nor.sh is present, copies it to /tmp/net.sh and executes it as root.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3:15 p.m.

5.4

CVSS3.1

CVE-2025-63834 -

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 8:15 p.m.

7.5

CVSS3.1

CVE-2025-63152 -

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternParameter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:07 p.m.

6.5

CVSS3.1

CVE-2025-56503 -

An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the uninstall file with a crafted binary in the installation folder. NOTE: this is disputed by the Supplier because replacing the uninsta…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-63147 -

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:16 p.m.

6.5

CVSS3.1

CVE-2025-63456 -

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:16 p.m.
Total resulsts: 348208
Page 2998 of 34,821
Β« previous page Β» next page
Filters