7.5

CVSS3.1

CVE-2025-61100 - frr: FRRouting: NULL Pointer Dereference in FRRouting

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 6:02 p.m.

9.8

CVSS3.1

CVE-2025-27224 -

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to write to any filename with any file ty…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:34 p.m.

8

CVSS3.1

CVE-2025-52263 -

An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted firmware, leading to arbitrary code execution.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2025-12343 - Ffmpeg: double-free vulnerability in ffmpeg tensorflow dnn backend

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free con…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 10:32 p.m.

7.5

CVSS3.1

CVE-2025-27223 -

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to s…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:35 p.m.

8.8

CVSS3.1

CVE-2023-49440 -

AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2025-60424 -

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 9 p.m.

7.5

CVSS3.1

CVE-2025-61105 - FRRouting: frr: NULL Pointer Dereference in FRRouting

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 5:48 p.m.

8.6

CVSS3.1

CVE-2025-60425 -

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 8:55 p.m.

10

CVSS3.1

CVE-2025-61481 -

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3280 of 34,919
Β« previous page Β» next page
Filters