Overview
Description
This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.
Statistics
- 1 Post
Last activity: 15 hours ago
Overview
- vercel
- next.js
21 Mar 2025
Published
08 Apr 2025
Updated
CVSS v3.1
CRITICAL (9.1)
EPSS
92.53%
KEV
Description
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
Statistics
- 1 Post
Last activity: 19 hours ago
Bluesky
📢 PCPcat : une campagne à grande échelle vole des identifiants sur des serveurs Next.js via CVE-2025-…📝 …
https://cyberveille.ch/posts/2025-12-21-pcpcat-une-campagne-a-grande-echelle-vole-des-identifiants-sur-des-serveurs-next-js-via-cve-2025-29927-66478-59-128-compromis/ #CVE_2025_29927 #Cyberveil…
Overview
Description
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Statistics
- 1 Post
Last activity: 11 hours ago
Fediverse
It is possible to see elevated activities targeting SeaCMS (CVE-2025-15002) https://vuldb.com/?ctiid.337707
Overview
- TP-Link Systems Inc.
- Tapo C200 V3
20 Dec 2025
Published
22 Dec 2025
Updated
CVSS v4.0
HIGH (7.1)
EPSS
Pending
KEV
Description
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulting in denial-of-service (DoS).
Statistics
- 1 Post
- 4 Interactions
Last activity: 5 hours ago
Overview
- TP-Link Systems Inc.
- Tapo C200 V3
20 Dec 2025
Published
22 Dec 2025
Updated
CVSS v4.0
HIGH (8.7)
EPSS
Pending
KEV
Description
The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
Statistics
- 1 Post
- 4 Interactions
Last activity: 5 hours ago
Overview
- TP-Link Systems Inc.
- Tapo C200 V3
20 Dec 2025
Published
22 Dec 2025
Updated
CVSS v4.0
HIGH (7.1)
EPSS
Pending
KEV
Description
A buffer overflow vulnerability exists in the ONVIF XML parser of Tapo C200 V3. An unauthenticated attacker on the same local network segment can send specially crafted SOAP XML requests, causing memory overflow and device crash, resulting in denial-of-service (DoS).
Statistics
- 1 Post
- 4 Interactions
Last activity: 5 hours ago