cve.li

Recent

CVE-2025-68474CWE-787

ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling

Published 2025-12-26 by GitHub_M

CVE-2025-68473CWE-787

ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling

Published 2025-12-26 by GitHub_M

CVE-2025-68148CWE-770

FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After

Published 2025-12-26 by GitHub_M

CVE-2025-68932CWE-338

FreshRSS has weak cryptographic randomness in remember-me token and nonce generation

Published 2025-12-26 by GitHub_M

CVE-2025-66203CWE-78

StreamVault is Vulnerable to Authenticated Remote Code Execution (RCE) via ytdlpargs Configuration Injection

Published 2025-12-26 by GitHub_M

CVE-2025-67729CWE-502

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

Published 2025-12-26 by GitHub_M

CVE-2025-68697CWE-269CWE-749

Self-hosted n8n has Legacy Code node that enables arbitrary file read/write

Published 2025-12-26 by GitHub_M

CVE-2025-68668CWE-693

n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node

Published 2025-12-26 by GitHub_M

CVE-2025-61914CWE-79

n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox

Published 2025-12-26 by GitHub_M

CVE-2025-13158CWE-1321

apidoc-core - prototype pollution in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker

Published 2025-12-26 by Sonatype

Load more ↓