7.5

CVSS3.1

CVE-2025-60663 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 5:34 p.m.

6.5

CVSS3.1

CVE-2025-57305 -

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:41 p.m.

6.5

CVSS3.1

CVE-2025-56019 -

An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without authentication. Once an unauthorized connection is established, legitimate applications are unable to connect, cau…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 27, 2025, 6:04 p.m.

7.2

CVSS3.1

CVE-2025-32942 -

SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2025-59406 -

The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a cleartext Auth0 client secret in its codebase. Because application binaries can be trivially decompiled or inspected, …

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 24, 2025, 5:27 p.m.

5.1

CVSS3.1

CVE-2025-57443 -

FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows escalated privileges…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-54315 -

The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-49090 -

The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-60662 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 5:44 p.m.

7.5

CVSS3.1

CVE-2025-56161 -

YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field filtering; because User.php defines no $hidden or $visible attributes, sensitive fields (bcrypt password hash, mobile num…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 6:33 p.m.
Total resulsts: 349182
Page 3598 of 34,919
Β« previous page Β» next page
Filters