6.5

CVSS3.1

CVE-2025-66174 -

There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and run a series of commands.

πŸ“… Published: Dec. 19, 2025, 6:39 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:45 a.m.

6.2

CVSS3.1

CVE-2025-66173 -

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shel…

πŸ“… Published: Dec. 19, 2025, 6:39 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:45 a.m.

5.6

CVSS4.0

CVE-2025-14267 - Unintended temporary cached data included in a structure only copy intended to be empty of data

Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7

πŸ“… Published: Dec. 19, 2025, 6:15 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6:15 a.m.

0.0

CVE-2025-13307 - Ocean Modal Window < 2.3.3 - Editor+ Remote Code Execution via Modal Conditions

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eva…

πŸ“… Published: Dec. 19, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 a.m.

6.9

CVSS4.0

CVE-2025-14546 -

Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth state parameter during the authentication callback. While the get_login_url method allows for state generation, it does not persist the state or bind it …

πŸ“… Published: Dec. 19, 2025, 5 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

6.9

CVSS4.0

CVE-2025-14940 - code-projects Scholars Tracking System delete_user.php sql injection

A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /admin/delete_user.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disc…

πŸ“… Published: Dec. 19, 2025, 4:02 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 4:02 a.m.

5.1

CVSS4.0

CVE-2025-14939 - code-projects Online Appointment Booking System deletemanager.php sql injection

A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the file /admin/deletemanager.php. The manipulation of the argument managername results in sql injection. The attack may be performed from remote. The exploit has been made public an…

πŸ“… Published: Dec. 19, 2025, 4:02 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 4:02 a.m.

8.8

CVSS3.1

CVE-2025-13941 - Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerab…

A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system permissions are assigned to resources used by the update service. A local attacker with low privileges could modify or replace these resources, which ar…

πŸ“… Published: Dec. 19, 2025, 1:51 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 1:51 a.m.

8.8

CVSS3.1

CVE-2025-52692 - Bypass Authentication

Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without login credentials.

πŸ“… Published: Dec. 19, 2025, 1:50 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 1:50 a.m.

5.3

CVSS4.0

CVE-2025-14910 - Edimax BR-6208AC FTP Daemon Service handle_retr path traversal

A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon Service. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. Edimax confirms this issue: "This product is …

πŸ“… Published: Dec. 19, 2025, 1:32 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 1:32 a.m.
Total resulsts: 323495
Page 9 of 32,350
Β« previous page Β» next page
Filters