9.4

CVSS3.1

CVE-2025-30135 -

An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings. By connecting to http://192.168.10.1/mnt/ex…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:23 p.m.

9.1

CVSS3.1

CVE-2025-29629 -

Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-8124 - deerwms deer-wms-2 unallocatedList sql injection

A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/unallocatedList. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be lau…

πŸ“… Published: July 24, 2025, 11:32 p.m. πŸ”„ Last Modified: Aug. 28, 2025, 10:52 a.m.

8.3

CVSS4.0

CVE-2025-7742 - Authentication Bypass in LG Innotek Camera

An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to upload an HTTP POST request to the devices non-volatile storage. This action may result in remote code execution that allows an attacker to run arbitrary commands on the target d…

πŸ“… Published: July 24, 2025, 11:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.2

CVSS3.1

CVE-2025-0250 - HCL IEM is affected by an authorization token sent in cookie vulnerability

HCL IEM is affected by an authorization token sent in cookie vulnerability.Β  A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.

πŸ“… Published: July 24, 2025, 11:28 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 7:55 p.m.

3.3

CVSS3.1

CVE-2025-0249 - HCL IEM is affected by an improper invalidation of access or JWT token vulnerability

HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.Β  A token was not invalidated which may allow attackers to access sensitive data without authorization.

πŸ“… Published: July 24, 2025, 11:19 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 7:55 p.m.

9.3

CVSS4.0

CVE-2025-54369 - Node-SAML SAML Authentication Bypass

Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify aut…

πŸ“… Published: July 24, 2025, 11:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-22165 -

This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high impact to confident…

πŸ“… Published: July 24, 2025, 10:30 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.9

CVSS4.0

CVE-2025-54379 - eKuiper API endpoints handling SQL queries with user-controlled table names.

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote at…

πŸ“… Published: July 24, 2025, 10:24 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:37 p.m.

8.5

CVSS4.0

CVE-2025-53940 - Quiet uses insecure, inconsistent verification on local backend token

Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own. In versions 6.1.0-alpha.4 and below, Quiet's API for backend/frontend communication was using an insecure, not constant-time comparison function for token…

πŸ“… Published: July 24, 2025, 10:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4527 of 34,919
Β« previous page Β» next page
Filters