7

CVSS4.0

CVE-2025-14553 - Password Hash Leak Could Lead to Unauthorized Access on Tapo 210 via Local Network

Exposure of password hashes through an unauthenticated API response in TP-Link Tapo C210 V.1.8 app on iOS and Android, allowing attackers to brute force the password in the local network.Β Issue can be mitigated through mobile application updates. Device firmware remains unchanged.

πŸ“… Published: Dec. 16, 2025, 6:38 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

9.9

CVSS3.1

CVE-2025-68270 - CourseLimitedStaff Role Allows Studio Access

The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are able to access and edit courses in studio if they are granted the role on an org rather than on a course, and CourseLimitedStaffRole users are able to …

πŸ“… Published: Dec. 16, 2025, 6:26 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.5

CVSS3.1

CVE-2025-68156 - Expr has Denial of Service via Unbounded Recursion in Builtin Functions

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the ev…

πŸ“… Published: Dec. 16, 2025, 6:24 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.5

CVSS3.1

CVE-2025-68155 - @vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on Developme…

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process …

πŸ“… Published: Dec. 16, 2025, 6:20 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

8.1

CVSS3.1

CVE-2025-68154 - Command Injection in fsSize() on Windows

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without saniti…

πŸ“… Published: Dec. 16, 2025, 6:18 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

8.3

CVSS4.0

CVE-2025-68150 - Parse Server has Server-Side Request Forgery (SSRF) in Instagram OAuth Adapter

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, the Instagram authentication adapter allows clients to specify a custom API URL via the `apiURL` parameter in `authData`. This enables SSRF attacks and …

πŸ“… Published: Dec. 16, 2025, 6:15 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

6.3

CVSS3.1

CVE-2025-68146 - filelock has TOCTOU race condition that allows symlink attacks during lock file creation

filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation …

πŸ“… Published: Dec. 16, 2025, 6:10 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.4

CVSS3.1

CVE-2025-46296 -

An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and downloading application logs. This vulnerability has been fully addressed in FileMaker Server 22.0.4.

πŸ“… Published: Dec. 16, 2025, 6:07 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 2:45 p.m.

9.8

CVSS3.1

CVE-2025-46295 -

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could pote…

πŸ“… Published: Dec. 16, 2025, 6:07 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.3

CVSS3.1

CVE-2025-46294 -

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerab…

πŸ“… Published: Dec. 16, 2025, 6:07 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 2:44 p.m.
Total resulsts: 323702
Page 93 of 32,371
Β« previous page Β» next page
Filters