5.1

CVSS3.1

CVE-2025-60855 -

Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privileges. NOTE: this is disputed by the Supplier because the integrity of updates is…

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-60358 -

radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 12:31 p.m.

8.2

CVSS3.1

CVE-2025-61536 -

FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause r…

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-61554 -

A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of service (host hypervisor crash) via a crafted PCI configuration space access.

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-61539 -

Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 12:12 p.m.

8.2

CVSS3.1

CVE-2025-61553 -

An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of service (host hypervisor crash) via a crafted PCI configuration space access. Given it's a heap overflow in a privileged hy…

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-61541 -

Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain into the reset emai…

πŸ“… Published: Oct. 16, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 10:20 p.m.

5.5

CVSS3.1

CVE-2025-43282 - Double Free Leading to Unexpected System Termination Across Apple's Operating Systems

A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to cause unexpected system termination.

πŸ“… Published: Oct. 15, 2025, 8 p.m. πŸ”„ Last Modified: April 27, 2026, 11:45 p.m.

5.5

CVSS3.1

CVE-2025-43313 - Logic flaw enables unauthorized access to sensitive user data in macOS

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

πŸ“… Published: Oct. 15, 2025, 8 p.m. πŸ”„ Last Modified: April 27, 2026, 11:45 p.m.

4.7

CVSS3.1

CVE-2025-43280 - Mail Remote Image Exposure in Lockdown Mode

The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail in Lockdown Mode.

πŸ“… Published: Oct. 15, 2025, 8 p.m. πŸ”„ Last Modified: April 27, 2026, 11:45 p.m.
Total resulsts: 349182
Page 3398 of 34,919
Β« previous page Β» next page
Filters