0.0

CVE-2025-65857 -

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

7.5

CVSS3.1

CVE-2025-66735 -

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 10:40 p.m.

9.8

CVSS3.1

CVE-2025-67418 -

ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default credentials, resulting in full administrative co…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 10:40 p.m.

5.4

CVSS3.1

CVE-2025-65837 -

PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 10:39 p.m.

4.3

CVSS3.1

CVE-2024-35321 -

MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parameter.

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 8:15 p.m.

0.0

CVE-2025-68328 - firmware: stratix10-svc: fix bug in saving controller data

In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix bug in saving controller data Fix the incorrect usage of platform_set_drvdata and dev_set_drvdata. They both are of the same data and overrides each other. This resulted in the rmmod of the svc driver…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 5:16 p.m.

8.8

CVSS3.1

CVE-2025-68645 -

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influe…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 10:39 p.m.

7.1

CVSS3.1

CVE-2025-66736 -

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an authorization bypass vulnerabili…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 10:39 p.m.

6.1

CVSS3.1

CVE-2025-65790 -

A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict script execution inside SVG content. When a victim opens a crafted SVG containing an inline <script> element, the browser …

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 10:39 p.m.

5.5

CVSS3.1

CVE-2025-68326 - drm/xe/guc: Fix stack_depot usage

In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix stack_depot usage Add missing stack_depot_init() call when CONFIG_DRM_XE_DEBUG_GUC is enabled to fix the following call stack: [] BUG: kernel NULL pointer dereference, address: 0000000000000000 [] Workqueue: d…

πŸ“… Published: Dec. 22, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 5:16 p.m.
Total resulsts: 324275
Page 69 of 32,428
Β« previous page Β» next page
Filters