8.7

CVSS4.0

CVE-2020-36872 - BACnet Test Server 1.01 Malformed BVLC Length DoS

BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP BVLC packet handling. The server fails to properly validate the BVLC Length field in incoming UDP BVLC frames on the default BACnet port (47808/udp). A remote unauthenticated atta…

πŸ“… Published: Nov. 26, 2025, 10:13 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 11:15 p.m.

8.7

CVSS4.0

CVE-2020-36873 - Astak CM-818T3 Unauthenticated Configuration Disclosure

Astak CM-818T3 2.4GHz wireless security surveillance cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. The endpoint permits remote download of a compressed configuration backup without requiring authentication or authorization.…

πŸ“… Published: Nov. 26, 2025, 10:13 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 11:15 p.m.

8.7

CVSS4.0

CVE-2020-36874 - ACE SECURITY WIP-90113 Unauthenticated Configuration Disclosure

ACE SECURITY WIP-90113 HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. The endpoint permits remote download of a compressed configuration backup without requiring authentication or authorization. The exposed backup may inc…

πŸ“… Published: Nov. 26, 2025, 10:12 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 11:15 p.m.

4.3

CVSS3.1

CVE-2025-6195 - Direct Request ('Forced Browsing') in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.

πŸ“… Published: Nov. 26, 2025, 7:46 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 8:15 p.m.

6.5

CVSS3.1

CVE-2025-7449 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with specific permissions to cause a denial of service condition through HTTP response processing.

πŸ“… Published: Nov. 26, 2025, 7:46 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 8:15 p.m.

7.5

CVSS3.1

CVE-2025-12571 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing malicious JSON payloa…

πŸ“… Published: Nov. 26, 2025, 7:46 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 8:15 p.m.

6.5

CVSS3.1

CVE-2025-12653 - Authentication Bypass by Spoofing in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.

πŸ“… Published: Nov. 26, 2025, 7:46 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 8:15 p.m.

2

CVSS3.1

CVE-2025-13611 - Insertion of Sensitive Information into Log File in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

πŸ“… Published: Nov. 26, 2025, 7:45 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 8:15 p.m.

6.9

CVSS4.0

CVE-2025-66028 - OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation

OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying thi…

πŸ“… Published: Nov. 26, 2025, 6:11 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 7:15 p.m.

8.8

CVSS4.0

CVE-2025-65966 - OneUptime Unauthorized User Creation via API

OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in version 9.1.0.

πŸ“… Published: Nov. 26, 2025, 6:10 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 7:15 p.m.
Total resulsts: 319564
Page 8 of 31,957
Β« previous page Β» next page
Filters