4.7

CVSS3.1

CVE-2025-55971 -

TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to a blind, unauthenticated Server-Side Request Forgery (SSRF) vulnerability via the UPnP MediaRenderer service (AVTransport:1). The device accepts unauthenticated SetAVTransportURI โ€ฆ

๐Ÿ“… Published: Oct. 3, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 15, 2025, 6:17 p.m.

6.1

CVSS3.1

CVE-2021-42193 -

nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.

๐Ÿ“… Published: Oct. 3, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 19, 2025, 5:07 p.m.

7.2

CVSS3.1

CVE-2025-60787 -

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.

๐Ÿ“… Published: Oct. 3, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:22 p.m.

6.1

CVSS3.1

CVE-2025-60450 -

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\editor\Uploader.class.php component. This security flaw allows attackers toโ€ฆ

๐Ÿ“… Published: Oct. 3, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 7, 2025, 3:36 p.m.

4.9

CVSS3.1

CVE-2025-60449 -

An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the applicationโ€™s source code but also potentiโ€ฆ

๐Ÿ“… Published: Oct. 3, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 8, 2025, 3:20 p.m.

8.7

CVSS4.0

CVE-2025-61668 - @plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user

Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a speciโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 9:46 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-61600 - Unbounded Memory Allocation in Stalwart IMAP parser

Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerability in the IMAP protocol parser which allows remote attackers to exhaust server memory, potentially triggering the system's out-of-memory (OOM) killer and causing a denial of servโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 9:30 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-61666 - Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File

Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to leakage of passwords or any file on the file systemโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 9:15 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-61665 - WeGIA: Broken Access Control in `get_relatorios_socios.php` Endpoint

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability, identified in the get_relatorios_socios.php endpoint. This vulnerability allows unauthenticated attackers to directly access sensitive personal and fโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 8:39 p.m. ๐Ÿ”„ Last Modified: Oct. 7, 2025, 3:41 p.m.

4.8

CVSS4.0

CVE-2025-61606 - WeGIA: Open Redirect Vulnerability in `control.php` endpoint

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the control.php endpoint, specifically in the nextPage parameter (metodo=listarUmnomeClasse=FuncionarioControle). This vulnerability allows atโ€ฆ

๐Ÿ“… Published: Oct. 2, 2025, 8:25 p.m. ๐Ÿ”„ Last Modified: Oct. 7, 2025, 3:41 p.m.
Total resulsts: 349182
Page 3588 of 34,919
ยซ previous page ยป next page
Filters