7.8

CVSS3.1

CVE-2025-60749 -

DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS3.1

CVE-2025-63675 -

cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 1:24 p.m.

7.5

CVSS3.1

CVE-2025-63465 -

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:29 p.m.

7.5

CVSS3.1

CVE-2025-63461 -

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:30 p.m.

7.5

CVSS3.1

CVE-2025-63454 -

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:29 p.m.

7.5

CVSS3.1

CVE-2025-63561 -

Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where an attacker that opens and maintains many slow or partially-completed HTTP connections can exhaust the server’s co…

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:32 p.m.

6.5

CVSS3.1

CVE-2025-63563 -

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:10 p.m.

7.5

CVSS3.1

CVE-2025-63459 -

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:29 p.m.

6.1

CVSS3.1

CVE-2025-61427 -

A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the userid and password parameters.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-63467 -

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:30 p.m.
Total resulsts: 349182
Page 3195 of 34,919
Β« previous page Β» next page
Filters