6.4

CVSS3.1

CVE-2025-58713 - Rhpam: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container,…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 1:55 p.m.

6.4

CVSS3.1

CVE-2025-57853 - Web-terminal: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root us…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 1:55 p.m.

6.4

CVSS3.1

CVE-2025-57854 - Osus-operator: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, ev…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 1:55 p.m.

6.4

CVSS3.1

CVE-2025-57851 - Mce: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container,…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 1:55 p.m.

6.4

CVSS3.1

CVE-2025-57847 - Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissi…

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 1:55 p.m.

7.4

CVSS3.1

CVE-2026-5795 -

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals. A subsequent requ…

📅 Published: April 8, 2026, 1:32 p.m. 🔄 Last Modified: April 8, 2026, 1:32 p.m.

6.4

CVSS3.1

CVE-2026-2509 - Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via But…

The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in the 'pagelayer_xss_content' XSS filtering function, whic…

📅 Published: April 8, 2026, 1:26 p.m. 🔄 Last Modified: April 8, 2026, 1:26 p.m.

9.3

CVSS4.0

CVE-2025-14816 - Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suit…

Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 a…

📅 Published: April 8, 2026, 1:23 p.m. 🔄 Last Modified: April 8, 2026, 1:23 p.m.

9.3

CVSS4.0

CVE-2025-14815 - Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suit…

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prio…

📅 Published: April 8, 2026, 1:15 p.m. 🔄 Last Modified: April 8, 2026, 1:20 p.m.

0.0

CVE-2026-31411 - net: atm: fix crash due to unvalidated vcc pointer in sigd_send()

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc pointer from msg->vcc and uses it directly without any validati…

📅 Published: April 8, 2026, 1:06 p.m. 🔄 Last Modified: April 8, 2026, 1:06 p.m.
Total resulsts: 343168
Page 1 of 34,317
» next page
Filters