5.1

CVSS3.1

CVE-2025-56802 -

The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the Supplier's position is th…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 4:04 p.m.

6.1

CVSS3.1

CVE-2025-60933 -

Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Descrip…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-52079 -

The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 7 p.m.

6.5

CVSS3.1

CVE-2025-56799 -

Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 12:46 p.m.

5.3

CVSS3.1

CVE-2025-59438 -

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 3:16 p.m.

6.1

CVSS3.1

CVE-2025-57521 -

Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without validating its digital signature or verifying its authenticity. A local attacker can exploit this behavior by placing a ma…

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-61194 -

daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 3:17 p.m.

6.1

CVSS3.1

CVE-2025-60934 -

Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee Notes, title, or description parameters. The patched …

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-61181 -

daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 3:16 p.m.

6.5

CVSS3.1

CVE-2025-60790 -

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.

πŸ“… Published: Oct. 21, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 8:08 p.m.
Total resulsts: 349182
Page 3361 of 34,919
Β« previous page Β» next page
Filters