9.8

CVSS3.1

CVE-2025-30127 -

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port 7777, and then downl…

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-51056 -

An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE).

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 5:36 p.m.

6.1

CVSS3.1

CVE-2025-51053 -

A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject arbitrary Javascript or HTML code and potentially trigger code execution in victim's browser.

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 5:35 p.m.

3.2

CVSS3.1

CVE-2025-45764 - jsrsasign: jsrsasign Weak Encryption Vulnerability

jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue has been disputed by a third party who believes that CVE IDs can be assigned for key lengths in specific applications that use a library, and should not be assigned to the default key lengths in a library. This dispute is…

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-51054 -

Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via sending an empty HTTP POST request to the /autologin/ API endpoint.

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 5:36 p.m.

6.5

CVSS3.1

CVE-2025-51058 -

Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows remote authenticated attackers to trigger HTTP requests towards arbitrary remote paths via the "file" URL parameter.

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 5:36 p.m.

5.3

CVSS3.1

CVE-2025-8419 - Org.keycloak/keycloak-services: keycloak smtp inject vulnerability

A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited local part of the email), so the attack is limited to very shorts emails (subjec…

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

7.5

CVSS3.1

CVE-2025-46659 -

An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request.

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 5:28 p.m.

7.5

CVSS3.1

CVE-2025-51532 -

Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:38 p.m.

6.5

CVSS3.1

CVE-2025-51306 -

In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without expiration, due to incorrect session management.

πŸ“… Published: Aug. 6, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 5:35 p.m.
Total resulsts: 349182
Page 4401 of 34,919
Β« previous page Β» next page
Filters