4.8

CVSS4.0

CVE-2025-64723 - Arduino IDE for macOS has TCC Bypass via Dynamic Library Injection

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic libraries into the ap…

📅 Published: Dec. 18, 2025, 3:15 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:15 p.m.

7.1

CVSS4.0

CVE-2025-65011 - Unauthorized Access to files in WODESYS WD-R608U router

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by directly referencing the resource in question. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version r…

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:10 p.m.

7.1

CVSS4.0

CVE-2025-65010 - Missing authorizations for admin panel password change in WODESYS WD-R608U router

WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) is vulnerable to Broken Access Control in initial configuration wizard.cgi endpoint. Malicious attacker can change admin panel password without authorization. The vulnerability can also be exploited after the initial configuration has b…

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:10 p.m.

7.1

CVSS4.0

CVE-2025-65009 - Insecure Password Storage in WODESYS WD-R608U router

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) admin password is stored in configuration file as plaintext and can be obtained by unauthorized user by direct references to the resource in question. The vendor was notified early about this vulnerability, but didn't respond with t…

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:10 p.m.

9.4

CVSS4.0

CVE-2025-65008 - OS Command Injection in WODESYS WD-R608U router

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in the adm.cgi endpoint, the malicious attacker can execute system shell commands. The vendor was notified early about this vulnerability, but didn't respond with the details of vul…

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:10 p.m.

8.7

CVSS4.0

CVE-2025-65007 - Missing Authentication for Critical Function in WODESYS WD-R608U router

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration change module in the adm.cgi endpoint, the unauthenticated attacker can execute commands including backup creation, device restart and resetting the device to factory settings. The …

📅 Published: Dec. 18, 2025, 3:10 p.m. 🔄 Last Modified: Dec. 19, 2025, 6 p.m.

0.0

CVE-2025-68325 - net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop In cake_drop(), qdisc_tree_reduce_backlog() is used to update the qlen and backlog of the qdisc hierarchy. Its caller, cake_enqueue(), assumes that the parent qdisc w…

📅 Published: Dec. 18, 2025, 3:02 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:02 p.m.

0.0

CVE-2025-68324 - scsi: imm: Fix use-after-free bug caused by unfinished delayed work

In the Linux kernel, the following vulnerability has been resolved: scsi: imm: Fix use-after-free bug caused by unfinished delayed work The delayed work item 'imm_tq' is initialized in imm_attach() and scheduled via imm_queuecommand() for processing SCSI commands. When the IMM parallel port SCSI…

📅 Published: Dec. 18, 2025, 3:02 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:02 p.m.

0.0

CVE-2025-68323 - usb: typec: ucsi: fix use-after-free caused by uec->work

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: fix use-after-free caused by uec->work The delayed work uec->work is scheduled in gaokun_ucsi_probe() but never properly canceled in gaokun_ucsi_remove(). This creates use-after-free scenarios where the ucsi and…

📅 Published: Dec. 18, 2025, 3:02 p.m. 🔄 Last Modified: Dec. 18, 2025, 3:02 p.m.

8.5

CVSS4.0

CVE-2025-64469 - Stack-based Buffer Overflow in LVResource::DetachResource() in NI LabVIEW

There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially…

📅 Published: Dec. 18, 2025, 2:53 p.m. 🔄 Last Modified: Dec. 18, 2025, 2:53 p.m.
Total resulsts: 323575
Page 31 of 32,358
« previous page » next page
Filters