CVE-2025-63896
An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject
CVSS
7.6
Alto
EPSS
0.3%
p22
KEV
—
Exploit Today
6
0-100
Publicado: 4 dic 2025 · Última mod.: 5 jul 2026 · CWE-306
0.3%EPSS · 30 días0.3%
2026-08-102026-09-07
An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-626459.8 CRÍ—
——0A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.7hCVE-2026-19397——
——0Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session.
Refer to the '
Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.13hCVE-2026-865439.8 CRÍ—
——0knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.17hCVE-2026-865065.9 MED—
——0In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data5hCVE-2026-865028.4 ALT—
——0In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts5hCVE-2026-864863.7 BAJ—
——0In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank5h