6.5

CVSS3.1

CVE-2025-6013 - Vault LDAP MFA Enforcement Bypass When Using Username As Alias

Vault and Vault Enterprise’s (β€œVault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and …

πŸ“… Published: Aug. 6, 2025, 10:06 a.m. πŸ”„ Last Modified: Aug. 7, 2025, 3:55 a.m.

9.3

CVSS4.0

CVE-2025-22470 -

CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrary Lua script may be executed on the system with the root privilege.

πŸ“… Published: Aug. 6, 2025, 9:52 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

6.9

CVSS4.0

CVE-2025-22469 -

OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1. An arbitrary OS command may be executed on the system with a certain non-administrative user privilege.

πŸ“… Published: Aug. 6, 2025, 9:52 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

8.7

CVSS4.0

CVE-2025-7771 - Code Execution / Escalation of Privileges in ThrottleStop

ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrar…

πŸ“… Published: Aug. 6, 2025, 9:35 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:25 p.m.

5.3

CVSS3.1

CVE-2025-8620 - GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id.

πŸ“… Published: Aug. 6, 2025, 9:22 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

3.7

CVSS3.1

CVE-2025-8556 - Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

πŸ“… Published: Aug. 6, 2025, 8:48 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:24 p.m.

5.1

CVSS4.0

CVE-2025-7202 - Cross-Site Request Forgery (CSRF) allowed remote control of Elgato Key Lights

A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.

πŸ“… Published: Aug. 6, 2025, 8:28 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

7.5

CVSS3.1

CVE-2025-47324 - Exposure of Sensitive Information Through Metadata in Powerline Communication Firmware

Information disclosure while accessing and modifying the PIB file of a remote device via powerline.

πŸ“… Published: Aug. 6, 2025, 7:26 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

7.8

CVSS3.1

CVE-2025-27076 - Time-of-check Time-of-use (TOCTOU) Race Condition in Display

Memory corruption while processing simultaneous requests via escape path.

πŸ“… Published: Aug. 6, 2025, 7:26 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

7.8

CVSS3.1

CVE-2025-27075 - Improper Validation of Array Index in Bluetooth HOST

Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.

πŸ“… Published: Aug. 6, 2025, 7:26 a.m. πŸ”„ Last Modified: Aug. 7, 2025, 7:16 a.m.
Total resulsts: 304555
Page 11 of 30,456
Β« previous page Β» next page
Filters