7.2

CVSS4.0

CVE-2025-41425 - DuraComm DP-10iN-100-MU Cross-site Scripting

DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack. This could allow an attacker to prevent legitimate users from accessing the web interface.

πŸ“… Published: July 22, 2025, 9:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-53538 - Suricata's mishandling of data on HTTP2 stream 0 can lead to resource starvation

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.0.10 and below and 8.0.0-beta1 through 8.0.0-rc1, mishandling of data on HTTP2 stream 0 can lead to uncontrolled memory usage, leading to loss of vis…

πŸ“… Published: July 22, 2025, 9:36 p.m. πŸ”„ Last Modified: Oct. 6, 2025, 3:48 p.m.

8.7

CVSS4.0

CVE-2025-48733 - DuraComm DP-10iN-100-MU Missing Authentication for Critical Function

DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication. This could allow an attacker to repeatedly reboot the device.

πŸ“… Published: July 22, 2025, 9:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-54141 - ViewVC's standalone server exposes arbitrary server filesystem content

ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the standalone.py script provided in the ViewVC distribution can expose the contents of the host server's filesystem though a directory traversal-style attack…

πŸ“… Published: July 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 5:17 p.m.

7.5

CVSS3.1

CVE-2025-54072 - yt-dlp allows `--exec` command injection when using placeholder on Windows

yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option is used on Windows with the default placeholder (or {}), insufficient sanitization is applied to the expanded filepath, allowing for remote code execution. This is a bypass of the …

πŸ“… Published: July 22, 2025, 9:34 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 3:59 p.m.

7.5

CVSS3.1

CVE-2025-54140 - pyLoad has Path Traversal Vulnerability in json/upload Endpoint that allows Arbitrary File Write

pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exists in the /json/upload endpoint of pyLoad. By manipulating the filename of an uploaded file, an attacker can traverse out of the intended upload dire…

πŸ“… Published: July 22, 2025, 9:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-54137 - NodeJS version of the HAX CMS application is distributed with Default Secrets

HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and superuser accounts. Additionally, the application has default private keys for JWTs. Users aren't prompted to change c…

πŸ“… Published: July 22, 2025, 9:34 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 3:20 p.m.

7.5

CVSS3.1

CVE-2025-54138 - LibreNMS has Authenticated Local File Inclusion in ajax_form.php that Allows RCE

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. LibreNMS versions 25.6.0 and below contain an architectural vulnerability in the ajax_form.php endpoint that permits Remote File Inclusion based…

πŸ“… Published: July 22, 2025, 9:33 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 5:52 p.m.

8.7

CVSS4.0

CVE-2025-53703 - DuraComm DP-10iN-100-MU Cleartext Transmission of Sensitive Information

DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted by attackers.

πŸ“… Published: July 22, 2025, 9:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-8011 -

Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: July 22, 2025, 9:11 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.
Total resulsts: 349182
Page 4546 of 34,919
Β« previous page Β» next page
Filters