7.2

CVSS3.1

CVE-2025-58179 - Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint

Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn't check the URLs …

πŸ“… Published: Sept. 4, 2025, 11:36 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.

2.1

CVSS4.0

CVE-2025-58352 - Weblate has long session expiry times during second factor verification

Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.

πŸ“… Published: Sept. 4, 2025, 11:28 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.

5.1

CVSS4.0

CVE-2025-55739 - api: Shared OAuth Signing Key Between Different Instances

api is a module for FreePBX@, which is an open source GUI that controls and manages AsteriskΒ© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key used across multiple systems that installed the same FreePBX RPM or DEB package. An…

πŸ“… Published: Sept. 4, 2025, 11:22 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.

9

CVSS3.1

CVE-2025-55241 - Azure Entra Elevation of Privilege Vulnerability

Azure Entra Elevation of Privilege Vulnerability

πŸ“… Published: Sept. 4, 2025, 11:09 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.

7.5

CVSS3.1

CVE-2025-55238 - Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability

Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability

πŸ“… Published: Sept. 4, 2025, 11:09 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.

10

CVSS3.1

CVE-2025-54914 - Azure Networking Elevation of Privilege Vulnerability

Azure Networking Elevation of Privilege Vulnerability

πŸ“… Published: Sept. 4, 2025, 11:09 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.

6.5

CVSS3.1

CVE-2025-55242 - Xbox Certification Bug Copilot Djando Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.

πŸ“… Published: Sept. 4, 2025, 11:09 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.

9

CVSS3.1

CVE-2025-55244 - Azure Bot Service Elevation of Privilege Vulnerability

Azure Bot Service Elevation of Privilege Vulnerability

πŸ“… Published: Sept. 4, 2025, 11:09 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.

6.1

CVSS3.1

CVE-2025-55305 - Electron is vulnerable to Code Injection via resource modification

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts…

πŸ“… Published: Sept. 4, 2025, 11:05 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.

5.1

CVSS4.0

CVE-2025-55209 - FreePBX UCP is Vulnerable to Stored XSS Through its User Control Panel

contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages AsteriskΒ© (PBX). In versions 15.0.14 and below, 16.0.0 through 16.0.26.4 and 17.0.0 through 17.0.5, a stored cross-site scripting (XSS) vulnerability in FreePBX allows a low-privileged User Control Panel…

πŸ“… Published: Sept. 4, 2025, 10:50 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:01 p.m.
Total resulsts: 309393
Page 108 of 30,940
Β« previous page Β» next page
Filters