9.3

CVSS4.0

CVE-2025-59374 -

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that m…

📅 Published: Dec. 17, 2025, 4:27 a.m. 🔄 Last Modified: Dec. 17, 2025, 8:50 p.m.

4.8

CVSS4.0

CVE-2025-11775 -

An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crafted requests, which may lead to a service crash or partial loss of functionality. This vulnerability only affects ASUS motherboard series products. Refer to …

📅 Published: Dec. 17, 2025, 4:25 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:45 p.m.

7

CVSS4.0

CVE-2025-11901 -

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and…

📅 Published: Dec. 17, 2025, 4:23 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:46 p.m.

5.1

CVSS4.0

CVE-2025-64700 -

Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.

📅 Published: Dec. 17, 2025, 4:06 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:33 p.m.

8.5

CVSS4.0

CVE-2025-14305 - Acer|ListCheck.exe - Local Privilege Escalation

ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malicious executable of the same name, which will be executed by the system and result in privilege escalation.

📅 Published: Dec. 17, 2025, 3:30 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:31 p.m.

7

CVSS4.0

CVE-2025-14304 - ASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism Failure

Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory b…

📅 Published: Dec. 17, 2025, 3:23 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:30 p.m.

6.4

CVSS3.1

CVE-2025-13977 - Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Co…

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input sanitization and output escaping in the Event Calen…

📅 Published: Dec. 17, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:27 p.m.

7

CVSS4.0

CVE-2025-14303 - MSI|Motherboard - Protection Mechanism Failure

Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are l…

📅 Published: Dec. 17, 2025, 3:13 a.m. 🔄 Last Modified: Dec. 17, 2025, 3:13 a.m.

7

CVSS4.0

CVE-2025-14302 - GIGABYTE|Motherboard - Protection Mechanism Failure

Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features …

📅 Published: Dec. 17, 2025, 3:07 a.m. 🔄 Last Modified: Dec. 17, 2025, 3:07 a.m.

4.8

CVSS4.0

CVE-2025-14801 - xiweicheng TMS create createComment cross site scripting

A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of the file /admin/blog/comment/create. Such manipulation of the argument content leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed…

📅 Published: Dec. 17, 2025, 2:02 a.m. 🔄 Last Modified: Dec. 17, 2025, 2:02 a.m.
Total resulsts: 323198
Page 38 of 32,320
« previous page » next page
Filters