9.8

CVSS3.1

CVE-2024-45162 -

A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the password field.

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-61156 -

Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL.

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3

CVSS3.1

CVE-2025-56558 -

The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct values of AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, and device serial number, even if a device (such as a Pure Hot+Cool device) has been removed and is not visib…

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-62229 - Xorg: xmayland: use-after-free in xpresentnotify structure creation

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an att…

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 4:30 p.m.

9.8

CVSS3.1

CVE-2025-63622 -

A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/admin/subcategory.php. This manipulation of the argument category causes SQL injection.

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 6:35 p.m.

8.2

CVSS3.1

CVE-2025-60595 -

SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-62231 - Xorg: xmayland: value overflow in xkbsetcompatmap()

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a cr…

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 3:30 p.m.

8.8

CVSS3.1

CVE-2025-61429 -

An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request.

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2025-61161 -

DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a crafted DLL in that…

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-60320 -

memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (memoQauhlp101). The affected service is installed with a path containing spaces and without surrounding quotes. This misconfiguration allows local users to escalate privileges to …

πŸ“… Published: Oct. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3233 of 34,919
Β« previous page Β» next page
Filters