8.2

CVSS3.1

CVE-2025-27919 -

An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later conne…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 6:09 p.m.

6.1

CVSS3.1

CVE-2025-12789 - Rhsso: open redirect

A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter associated with the openid-connect logout protocol does not properly validate the provided URL.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 5:59 p.m.

6.8

CVSS3.1

CVE-2025-59392 -

On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

8.1

CVSS3.1

CVE-2025-63307 -

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:19 p.m.

7.4

CVSS3.1

CVE-2025-12790 - Rubygem-mqtt: rubygem-mqtt hostname validation

A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 8, 2025, 4:55 a.m.

7.1

CVSS3.1

CVE-2025-63588 -

An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of s…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 10:55 a.m.

7.1

CVSS3.1

CVE-2025-63589 -

A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are not sanitized or encoded before being inserted into the generated HTML (navigation links, breadcrumbs, search form action, footer links). An attacker-controlled string placed in the…

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 10:55 a.m.

0.0

CVE-2025-63560 -

An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 8:38 p.m.

7.5

CVSS3.1

CVE-2025-27917 -

An issue was discovered in AnyDesk through 9.0.4. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 6:07 p.m.

9.8

CVSS3.1

CVE-2025-27918 -

An issue was discovered in AnyDesk before 9.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients.

πŸ“… Published: Nov. 6, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 6:08 p.m.
Total resulsts: 317465
Page 43 of 31,747
Β« previous page Β» next page
Filters