6.5

CVSS3.1

CVE-2025-63617 -

ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3:10 p.m.

4.5

CVSS3.1

CVE-2025-63712 -

Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF prot…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:16 p.m.

5.4

CVSS3.1

CVE-2025-63709 -

A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text input. An authenticated user can submit HTML/JavaScript that is not correctly sanitized or encoded on output. The injected script is stored and later rendered in the browser of a…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 8:15 p.m.

7.5

CVSS3.1

CVE-2025-63149 -

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:08 p.m.

6.5

CVSS3.1

CVE-2025-63384 -

A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3:25 p.m.

6.5

CVSS3.1

CVE-2025-63457 -

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:16 p.m.

7.1

CVSS3.1

CVE-2025-63711 -

A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g., superadmin_user_dele…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:16 p.m.

6.5

CVSS3.1

CVE-2025-63710 -

The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms such as tokens, nonces, or same-site cookie restrictions. An attacker can create a malicious HTML page th…

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:18 p.m.

6.5

CVSS3.1

CVE-2025-63296 -

KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh scans mounted TF/SD cards and, if /mnt/update.nor.sh is present, copies it to /tmp/net.sh and executes it as root.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3:15 p.m.

5.4

CVSS3.1

CVE-2025-63834 -

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.

πŸ“… Published: Nov. 10, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 8:15 p.m.
Total resulsts: 349182
Page 3095 of 34,919
Β« previous page Β» next page
Filters