7.5

CVSS3.1

CVE-2025-61099 - FRRouting: frr: NULL Pointer Dereference in FRRouting

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

5.4

CVSS3.1

CVE-2025-60983 -

Reflected Cross Site Scripting vulnerability in Rubikon Banking Solution 4.0.3 in the "Search For Customers Information" endpoints.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

0.0

CVE-2025-52264 -

StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 2:14 p.m.

7.5

CVSS3.1

CVE-2025-61105 - FRRouting: frr: NULL Pointer Dereference in FRRouting

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-61101 - FRRouting: frr: NULL Pointer Dereference in FRRouting

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-52268 -

StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tokens.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

6.1

CVSS3.1

CVE-2025-54965 -

An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize the job ID parameter before using it in the job status page. An attacker who is able to social engineer a user into clicking a malicious link may be able to execute arbitrary Jav…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

3.3

CVSS3.1

CVE-2025-12343 - FFmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free con…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 27, 2025, midnight

6.1

CVSS3.1

CVE-2025-54969 -

An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into clicking a malicious link or visiting a malicious website may be able to submit requests to the Job Status Service withou…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-27223 -

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to s…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.
Total resulsts: 316435
Page 83 of 31,644
Β« previous page Β» next page
Filters