8.8

CVSS3.1

CVE-2025-55847 -

Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerability arises because the Cookie parameter does not properly validate the length of input data. Attackers can exploit this to execute arbitrary code or cause a denial of service (D…

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 7:22 p.m.

9.9

CVSS3.1

CVE-2025-55187 -

In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: Oct. 8, 2025, 8:20 p.m.

7.5

CVSS3.1

CVE-2025-11021 - Libsoup: out-of-bounds read in cookie date handling of libsoup http library

A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in uninten…

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-55848 -

An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parameter is not filtered by '&'to allow injection of reverse connection commands.

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: March 9, 2026, 3:18 p.m.

7.1

CVSS3.1

CVE-2025-58385 -

In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded and predictable data).

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 6:51 p.m.

8.2

CVSS3.1

CVE-2025-60017 -

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-56463 -

Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 6:52 p.m.

10

CVSS3.1

CVE-2025-58384 -

In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .NET Remoting library in the Watchdoc administration interface.

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-59362 - squid-cache: Squid cache buffer overflow

Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 6:50 p.m.

4.7

CVSS3.1

CVE-2025-60250 -

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554124a key and the 2841ae97419c2973296a0d4bdfe19a4f IV.

πŸ“… Published: Sept. 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3678 of 34,919
Β« previous page Β» next page
Filters