8.1

CVSS3.1

CVE-2025-39889 - Bluetooth: l2cap: Check encryption key size on incoming connection

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on incoming connection This is required for passing GAP/SEC/SEM/BI-04-C PTS test case: Security Mode 4 Level 4, Responder - Invalid Encryption Key Size - 128 bit This tests the sec…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 9:16 a.m.

7.5

CVSS3.1

CVE-2025-57327 -

spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config function of spmrc version 1.2.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum con…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 4:50 p.m.

6.5

CVSS3.1

CVE-2025-57324 -

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of servi…

πŸ“… Published: Sept. 24, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:48 p.m.

8.2

CVSS4.0

CVE-2025-57882 - AutomationDirect CLICK PLUS Improper Resource Shutdown or Release

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions in the Remote PLC appl…

πŸ“… Published: Sept. 23, 2025, 10:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS4.0

CVE-2025-55038 - AutomationDirect CLICK PLUS Missing Authorization

An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Through the KOPR protocol utilized by the Remote PLC application, authenticated users with low-level access permissions can exploit this vulnerability to read and modify PLC variables…

πŸ“… Published: Sept. 23, 2025, 10:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2025-58473 - AutomationDirect CLICK PLUS Improper Resource Shutdown or Release

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions of the Click Programmi…

πŸ“… Published: Sept. 23, 2025, 10:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-55069 - AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator

A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises the security of the g…

πŸ“… Published: Sept. 23, 2025, 10:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-59484 - AutomationDirect CLICK PLUS Use of a Broken or Risky Cryptographic Algorithm

The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software uses an insecure implementation of the RSA encryption algorithm.

πŸ“… Published: Sept. 23, 2025, 10:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-58069 - AutomationDirect CLICK PLUS Use of Hard-coded Cryptographic Key

The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software contains a hard-coded AES key used to protect the initial messages of a new KOPS session.

πŸ“… Published: Sept. 23, 2025, 10:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.1

CVSS4.0

CVE-2025-54855 - AutomationDirect CLICK PLUS Cleartext Storage of Sensitive Information

Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to the file system, while an administrator session is active, to steal credentials stored in clear text.

πŸ“… Published: Sept. 23, 2025, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3703 of 34,919
Β« previous page Β» next page
Filters