9.6

CVSS3.1

CVE-2025-67787 -

An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:35 p.m.

0.0

CVE-2025-66953 -

CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interface and specifically the /system_setup.htm, /set_clock.htm, /receiver_setup.htm, /cal.htm?..., and /channel_setup.htm endpoints

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:57 a.m.

0.0

CVE-2025-67791 -

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 9:22 p.m.

0.0

CVE-2024-46060 -

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary comma…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:57 a.m.

5.3

CVSS3.1

CVE-2024-29370 -

In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significan…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:57 a.m.

7.1

CVSS3.1

CVE-2025-65203 -

KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated form fields and exfiltrate credentials.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 9:18 p.m.

0.0

CVE-2025-67793 -

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This privilege is included by default in the Administr…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 9:16 p.m.

7.2

CVSS3.1

CVE-2025-67172 -

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 9:18 p.m.

0.0

CVE-2025-67074 -

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serverName`) to /goform/AdvSetMacMtuWan.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:57 a.m.

6.1

CVSS3.1

CVE-2025-65233 -

Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:48 p.m.
Total resulsts: 323602
Page 81 of 32,361
Β« previous page Β» next page
Filters