7.5

CVSS3.1

CVE-2025-48704 -

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

๐Ÿ“… Published: Dec. 25, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 7:29 p.m.

8.2

CVSS3.1

CVE-2025-59683 -

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.

๐Ÿ“… Published: Dec. 25, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 7:07 p.m.

7.5

CVSS3.1

CVE-2025-66443 -

Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.

๐Ÿ“… Published: Dec. 25, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 6:43 p.m.

7.4

CVSS3.1

CVE-2025-68922 -

OpenOps before 0.6.11 allows remote code execution in the Terraform block.

๐Ÿ“… Published: Dec. 24, 2025, 11:05 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-15073 - itsourcecode Online Frozen Foods Ordering System contact_us.php sql injection

A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and โ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 11:02 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:04 a.m.

8.9

CVSS3.1

CVE-2025-68920 -

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

๐Ÿ“… Published: Dec. 24, 2025, 9:47 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS3.1

CVE-2025-68919 -

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality, integrity, and avaiโ€ฆ

๐Ÿ“… Published: Dec. 24, 2025, 9:01 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-68917 -

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

๐Ÿ“… Published: Dec. 24, 2025, 8:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-8769 - MegaSys Computer Technologies Telenium Online Web Application Improper Input Validation

Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server.

๐Ÿ“… Published: Dec. 24, 2025, 8:14 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-3232 - Mitsubishi Electric Europe smartRTU Missing Authentication for Critical Function

A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands.

๐Ÿ“… Published: Dec. 24, 2025, 7:55 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344963
Page 1987 of 34,497
ยซ previous page ยป next page
Filters