3.8

CVSS3.1

CVE-2025-57807 - ImageMagick BlobStream Forward-Seek Under-Allocation

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then ex…

πŸ“… Published: Sept. 5, 2025, 9:16 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:16 p.m.

6.5

CVSS3.1

CVE-2025-10061 - Malformed $group Query May Cause MongoDB Server to Crash

An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect handling of certain accumulator functions when additional parameters are specified within the $group operation. This vulnerability could lead to denial…

πŸ“… Published: Sept. 5, 2025, 8:48 p.m. πŸ”„ Last Modified: Nov. 13, 2025, 4:58 p.m.

6.5

CVSS3.1

CVE-2025-10060 - MongoDB may be susceptible to Invariant Failure in Transactions due Upsert Operation

MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management. This issue affects MongoDB Server v6.0 ver…

πŸ“… Published: Sept. 5, 2025, 8:39 p.m. πŸ”„ Last Modified: Sept. 18, 2025, 4:14 p.m.

4.7

CVSS3.1

CVE-2025-53791 - Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

πŸ“… Published: Sept. 5, 2025, 8:28 p.m. πŸ”„ Last Modified: Feb. 20, 2026, 4:01 p.m.

6.5

CVSS3.1

CVE-2025-10059 - MongoDB Server router will crash when incorrect lsid is set on a sharded query

An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 a…

πŸ“… Published: Sept. 5, 2025, 8:26 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 4:55 p.m.

5.1

CVSS4.0

CVE-2025-10026 - itsourcecode POS Point of Sale System -complex_header.php cross site scripting

A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The manipulation of the argument scripts results in cross site scripting. It …

πŸ“… Published: Sept. 5, 2025, 8:02 p.m. πŸ”„ Last Modified: Sept. 10, 2025, 4:45 p.m.

6.9

CVSS4.0

CVE-2025-10025 - PHPGurukul Online Course Registration semester.php sql injection

A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument semester leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the publi…

πŸ“… Published: Sept. 5, 2025, 7:32 p.m. πŸ”„ Last Modified: Sept. 10, 2025, 4:47 p.m.

6.4

CVSS3.1

CVE-2025-9057 - Biagiotti Core <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Biagiotti Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-lev…

πŸ“… Published: Sept. 5, 2025, 6:23 p.m. πŸ”„ Last Modified: April 20, 2026, 7:45 p.m.

9.2

CVSS4.0

CVE-2025-35452 - Pan-Tilt-Zoom cameras default administrative credentials for web interface

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.

πŸ“… Published: Sept. 5, 2025, 5:49 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 5:08 p.m.

2.3

CVSS4.0

CVE-2025-30198 - ECOVACS Vacuum and Base Station Hard-Coded WPA2-PSK

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

πŸ“… Published: Sept. 5, 2025, 5:45 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 5:11 p.m.
Total resulsts: 349182
Page 3977 of 34,919
Β« previous page Β» next page
Filters