8.4

CVSS4.0

CVE-2025-53524 - Fuji Electric Monitouch V-SFT-6 Out-of-bounds Write

Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

πŸ“… Published: Dec. 17, 2025, 12:19 a.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

9.9

CVSS3.1

CVE-2025-14700 - Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller

An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.

πŸ“… Published: Dec. 17, 2025, 12:04 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:17 p.m.

7.1

CVSS3.1

CVE-2025-14701 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Cont…

An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.

πŸ“… Published: Dec. 17, 2025, 12:04 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:22 p.m.

9.8

CVSS3.1

CVE-2022-23851 -

Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:07 p.m.

7.2

CVSS3.1

CVE-2025-66923 -

A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:52 p.m.

7.5

CVSS3.1

CVE-2024-29371 -

In jose4j before 0.9.5, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during …

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 9:18 a.m.

9.8

CVSS3.1

CVE-2025-67073 -

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:07 p.m.

6.6

CVSS3.1

CVE-2025-65855 -

The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attacker with brief physical access can activate O…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:07 p.m.

7.8

CVSS3.1

CVE-2024-46062 -

Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary…

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:16 p.m.

6.5

CVSS3.1

CVE-2025-67074 -

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serverName`) to /goform/AdvSetMacMtuWan.

πŸ“… Published: Dec. 17, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:16 p.m.
Total resulsts: 323822
Page 99 of 32,383
Β« previous page Β» next page
Filters