2.3

CVSS3.1

CVE-2025-8448 -

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.

πŸ“… Published: Aug. 20, 2025, 1:58 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 10:27 p.m.

4.1

CVSS4.0

CVE-2025-8449 -

CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticated user sends a specially crafted request to a specific endpoint from within the BMS network.

πŸ“… Published: Aug. 20, 2025, 1:55 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 10:27 p.m.

4.9

CVSS3.1

CVE-2025-54927 -

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers uses a crafted path input that is processed by the system.

πŸ“… Published: Aug. 20, 2025, 1:51 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 10:27 p.m.

7.2

CVSS3.1

CVE-2025-54926 -

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution when an authenticated attacker with admin privileges uploads a malicious file over HTTP which then gets executed.

πŸ“… Published: Aug. 20, 2025, 1:48 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 10:27 p.m.

7.5

CVSS3.1

CVE-2025-54925 -

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures the application to access a malicious url.

πŸ“… Published: Aug. 20, 2025, 1:44 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 10:27 p.m.

7.5

CVSS3.1

CVE-2025-54924 -

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker sends a specially crafted document to a vulnerable endpoint.

πŸ“… Published: Aug. 20, 2025, 1:39 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 10:27 p.m.

8.7

CVSS4.0

CVE-2025-54923 -

CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.

πŸ“… Published: Aug. 20, 2025, 1:30 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 10:27 p.m.

9.3

CVSS4.0

CVE-2025-9074 - Docker Desktop allows unauthenticated access to Docker Engine API from containers

A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled, and with or without th…

πŸ“… Published: Aug. 20, 2025, 1:28 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 4:22 p.m.

7.2

CVSS3.1

CVE-2025-31355 -

A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“… Published: Aug. 20, 2025, 1:09 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 6:22 p.m.

8.1

CVSS3.1

CVE-2025-24322 -

An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lead to arbitrary code execution. An attacker can browse to the device to trigger this vulnerability.

πŸ“… Published: Aug. 20, 2025, 1:09 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 6:24 p.m.
Total resulsts: 307090
Page 76 of 30,709
Β« previous page Β» next page
Filters