6.5

CVSS3.1

CVE-2025-61224 -

Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-60964 -

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive information, and possibly other unspecified impacts.

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:14 p.m.

7.3

CVSS3.1

CVE-2025-60958 -

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:36 p.m.

9.9

CVSS3.1

CVE-2025-60957 -

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:36 p.m.

5.8

CVSS3.1

CVE-2025-59452 -

The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-59448 -

Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink โ€ฆ

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.6

CVSS3.1

CVE-2025-61985 - openssh: From CVEorg collector

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-61198 -

A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Optimod Trio - Optimod version 1.0.0.33 - System version 2.5.26, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payloaโ€ฆ

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS3.1

CVE-2025-61197 -

An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26 allows a remote attacker to escalate privileges via the application stores user privilege/role information in client-side browser storage

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-60961 -

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

๐Ÿ“… Published: Oct. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:35 p.m.
Total resulsts: 349182
Page 3549 of 34,919
ยซ previous page ยป next page
Filters