Products: 4
Vulnerabilities: 24
Known Exploited: 0
7
Critical Level Threats
3
High Level Threats
9
Medium Level Threats
5
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2025-63951
An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. This allows a remote, unauthenticated attacker to inject arbitrary PHP objects, causing the application to process them and leading to errors or a denial of service.
Last Modified: Dec 31, 2025
Published: Dec 18, 2025
CVE-2025-10370
MiczFlor RPi-Jukebox-RFID userScripts.php cross site scripting
Last Modified: Feb 03, 2026
Published: Sep 13, 2025
CVE-2025-10369
MiczFlor RPi-Jukebox-RFID cardRegisterNew.php cross site scripting
Last Modified: Oct 16, 2025
Published: Sep 13, 2025
CVE-2025-10368
MiczFlor RPi-Jukebox-RFID manageFilesFolders.php cross site scripting
Last Modified: Oct 16, 2025
Published: Sep 13, 2025
CVE-2025-10367
MiczFlor RPi-Jukebox-RFID cardEdit.php cross site scripting
Last Modified: Oct 16, 2025
Published: Sep 13, 2025
Items Per Page
