4.8

CVSS4.0

CVE-2025-8920 - Portabilis i-Diario Dicionรกrio de Termos BNCC dicionario-de-termos-bncc cross site scripting

A vulnerability was identified in Portabilis i-Diario 1.6. Affected by this vulnerability is an unknown functionality of the file /dicionario-de-termos-bncc of the component Dicionรกrio de Termos BNCC Page. The manipulation of the argument Planos de ensino leads to cross site scripting. The attack cโ€ฆ

๐Ÿ“… Published: Aug. 13, 2025, 6:02 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 12:50 p.m.

7.3

CVSS4.0

CVE-2024-5477 -

A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure via a physical attack that requires specialized equipment and knowledge. HP is releasingโ€ฆ

๐Ÿ“… Published: Aug. 13, 2025, 5:47 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 1:12 p.m.

8.7

CVSS4.0

CVE-2025-8754 - ABB AbilityTM zenon Remote Transport Vulnerability

Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.

๐Ÿ“… Published: Aug. 13, 2025, 5:40 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 1:11 p.m.

7.8

CVSS3.1

CVE-2025-23306 -

NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an attacker could cause a code injection issue by providing a malicious input. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, informโ€ฆ

๐Ÿ“… Published: Aug. 13, 2025, 5:35 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 12:50 p.m.

7.8

CVSS3.1

CVE-2025-23305 -

NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.

๐Ÿ“… Published: Aug. 13, 2025, 5:35 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 12:50 p.m.

4.8

CVSS4.0

CVE-2025-8919 - Portabilis i-Diario History objetivos-de-aprendizagem-e-habilidades cross site scripting

A vulnerability was determined in Portabilis i-Diario up to 1.6. Affected is an unknown function of the file /objetivos-de-aprendizagem-e-habilidades of the component History Page. The manipulation of the argument cรณdigo/objetivo habilidade leads to cross site scripting. It is possible to launch thโ€ฆ

๐Ÿ“… Published: Aug. 13, 2025, 5:32 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 12:50 p.m.

7.8

CVSS3.1

CVE-2025-23298 -

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

๐Ÿ“… Published: Aug. 13, 2025, 5:28 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 1:12 p.m.

6.5

CVSS3.1

CVE-2024-10219 - Incorrect Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

๐Ÿ“… Published: Aug. 13, 2025, 5:28 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 1:12 p.m.

6.7

CVSS3.1

CVE-2024-12303 - Incorrect Privilege Assignment in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting uโ€ฆ

๐Ÿ“… Published: Aug. 13, 2025, 5:27 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 1:12 p.m.

6.5

CVSS3.1

CVE-2025-1477 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

๐Ÿ“… Published: Aug. 13, 2025, 5:27 p.m. ๐Ÿ”„ Last Modified: Aug. 14, 2025, 1:12 p.m.
Total resulsts: 306430
Page 112 of 30,643
ยซ previous page ยป next page
Filters