24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture
📢 CVE-2025-14282 : élévation de privilèges dans Dropbear via redirections de sockets UNIX 📝 Source : oss-sec (mailing list). https://cyberveille.ch/posts/2025-12-21-cve-2025-14282-elevation-de-privileges-dans-dropbear-via-redirections-de-sockets-unix/ #CVE_2025_14282 #Cyberveille
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • vercel
  • next.js

21 Mar 2025
Published
08 Apr 2025
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
92.53%

KEV

Description

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture
📢 PCPcat : une campagne à grande échelle vole des identifiants sur des serveurs Next.js via CVE-2025-…📝 … https://cyberveille.ch/posts/2025-12-21-pcpcat-une-campagne-a-grande-echelle-vole-des-identifiants-sur-des-serveurs-next-js-via-cve-2025-29927-66478-59-128-compromis/ #CVE_2025_29927 #Cyberveil…
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • SeaCMS

21 Dec 2025
Published
22 Dec 2025
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
Pending

KEV

Description

A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture

It is possible to see elevated activities targeting SeaCMS (CVE-2025-15002) vuldb.com/?ctiid.337707

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • TP-Link Systems Inc.
  • Tapo C200 V3

20 Dec 2025
Published
22 Dec 2025
Updated

CVSS v4.0
HIGH (7.1)
EPSS
Pending

KEV

Description

The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulting in denial-of-service (DoS).

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 5 hours ago

Overview

  • TP-Link Systems Inc.
  • Tapo C200 V3

20 Dec 2025
Published
22 Dec 2025
Updated

CVSS v4.0
HIGH (8.7)
EPSS
Pending

KEV

Description

The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 5 hours ago

Overview

  • TP-Link Systems Inc.
  • Tapo C200 V3

20 Dec 2025
Published
22 Dec 2025
Updated

CVSS v4.0
HIGH (7.1)
EPSS
Pending

KEV

Description

A buffer overflow vulnerability exists in the ONVIF XML parser of Tapo C200 V3. An unauthenticated attacker on the same local network segment can send specially crafted SOAP XML requests, causing memory overflow and device crash, resulting in denial-of-service (DoS).

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 5 hours ago
Showing 31 to 36 of 36 CVEs