9.8

CVSS3.1

CVE-2024-53496 -

Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 7:39 p.m.

9.8

CVSS3.1

CVE-2024-50645 -

MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-38666 - net: appletalk: Fix use-after-free in AARP proxy probe

In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix use-after-free in AARP proxy probe The AARP proxy‐probe routine (aarp_proxy_probe_network) sends a probe, releases the aarp_lock, sleeps, then re-acquires the lock. During that window an expire timer thread (…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 5:31 p.m.

5.5

CVSS3.1

CVE-2025-38643 - wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac()

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac() Callers of wdev_chandef() must hold the wiphy mutex. But the worker cfg80211_propagate_cac_done_wk() never takes the lock. Which triggers the warning below with th…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:15 p.m.

4

CVSS3.1

CVE-2025-55631 -

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system wide instead of an account-by-account basis, potentially leading to a Denial of Service (DoS) via resource exhaustion. NOTE: the Supplier reports that the syst…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-55630 -

A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 when entering the wrong username and password allows attackers to enumerate existing accounts.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 2:04 p.m.

6.5

CVSS3.1

CVE-2025-55621 -

An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access and download other users' profile photos via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior; the photos are part of a social platf…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 1:58 a.m.

8.8

CVSS3.1

CVE-2025-55573 -

QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Sept. 15, 2025, 7:49 p.m.

8.8

CVSS3.1

CVE-2025-52287 -

OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 7:25 p.m.

6.1

CVSS3.1

CVE-2025-50859 -

Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Sept. 24, 2025, 5:55 p.m.
Total resulsts: 349182
Page 4176 of 34,919
Β« previous page Β» next page
Filters