Latest CVE Feed
-
8.6
HIGHCVE-2025-10653
An unauthenticated debug port may allow access to the device file system.... Read more
Affected Products :- Published: Oct. 02, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Misconfiguration
-
8.6
HIGHCVE-2025-59835
LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/files/documents interface to perform arbitrary file uploads. Since this interface does not strictly restri... Read more
Affected Products :- Published: Oct. 02, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-54315
The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.... Read more
Affected Products :- Published: Oct. 02, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-49090
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.... Read more
Affected Products :- Published: Oct. 02, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-32942
SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.... Read more
Affected Products : tectia_server- Published: Oct. 02, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2025-56019
An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without authentication. Once an unauthorized connection is established, legiti... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 27, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-60663
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-60661
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-59409
Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.... Read more
Affected Products : license_plate_reader_firmware- Published: Oct. 02, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-59407
The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a Java Keystore (flock_rye.bks) along with its hardcoded... Read more
Affected Products : flock_safety- Published: Oct. 02, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Cryptography
-
6.2
MEDIUMCVE-2025-59406
The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a cleartext Auth0 client secret in its codebase. Because application binarie... Read more
Affected Products : flock_safety- Published: Oct. 02, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-59405
The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a cleartext DataDog API key within in its codebase. Because ap... Read more
Affected Products : flock_safety- Published: Oct. 02, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-59403
The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoints on port 8080... Read more
Affected Products : flock_safety- Published: Oct. 02, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-34210
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, Portainer admin password, etc.) in cleartext files that ar... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Information Disclosure
-
8.2
HIGHCVE-2025-34208
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords using unsalted SHA-512 hashes with a fall-back to unsalted SHA-1. The hashing is performed via PHP's `hash()` function in multiple files... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Cryptography
-
7.5
HIGHCVE-2025-60662
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-60660
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-57305
VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.... Read more
Affected Products : vitaracharts- Published: Oct. 02, 2025
- Modified: Oct. 16, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2025-56162
YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modif... Read more
Affected Products : yoshop2.0- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-56161
YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field filtering; because User.php defines no $hidden or $visible attributes, sensit... Read more
Affected Products : yoshop2.0- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Information Disclosure