9.4
CVE-2025-30135 -
An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings. By connecting to http://192.168.10.1/mnt/exβ¦
9.1
CVE-2025-29629 -
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.
5.3
CVE-2025-8124 - deerwms deer-wms-2 unallocatedList sql injection
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/unallocatedList. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be lauβ¦
8.3
CVE-2025-7742 - Authentication Bypass in LG Innotek Camera
An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to upload an HTTP POST request to the devices non-volatile storage. This action may result in remote code execution that allows an attacker to run arbitrary commands on the target dβ¦
2.2
CVE-2025-0250 - HCL IEM is affected by an authorization token sent in cookie vulnerability
HCL IEM is affected by an authorization token sent in cookie vulnerability.Β A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.
3.3
CVE-2025-0249 - HCL IEM is affected by an improper invalidation of access or JWT token vulnerability
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.Β A token was not invalidated which may allow attackers to access sensitive data without authorization.
9.3
CVE-2025-54369 - Node-SAML SAML Authentication Bypass
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify autβ¦
5.9
CVE-2025-22165 -
This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high impact to confidentβ¦
8.9
CVE-2025-54379 - eKuiper API endpoints handling SQL queries with user-controlled table names.
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote atβ¦
8.5
CVE-2025-53940 - Quiet uses insecure, inconsistent verification on local backend token
Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own. In versions 6.1.0-alpha.4 and below, Quiet's API for backend/frontend communication was using an insecure, not constant-time comparison function for tokenβ¦