7.2

CVSS3.1

CVE-2025-63909 -

Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and read and write arbitrary files.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 5, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2026-3543 - chromium-browser: Inappropriate implementation in V8

Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 1:15 p.m.

7.5

CVSS3.1

CVE-2025-70239 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 8:16 p.m.

7.5

CVSS3.1

CVE-2025-69765 -

Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 4, 2026, 2:55 p.m.

7.5

CVSS3.1

CVE-2025-62817 -

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 10, 2026, 6:17 p.m.

9.1

CVSS3.1

CVE-2025-66945 -

A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extract, files may be written outside the intended directory, leading to arbitrary file overwrite and potentially remote code execution

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 4, 2026, 9:04 p.m.

5.3

CVSS3.1

CVE-2025-70236 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 4, 2026, 9:16 p.m.

5.3

CVSS3.1

CVE-2024-55023 -

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 6:16 p.m.

7.2

CVSS3.1

CVE-2025-67840 -

Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_1757588060_SEP2025_FULL.depot web application API endpoints (including Scheduler and Actions pages). The appliance directly concatenates user-controlled parame…

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 5, 2026, 12:15 a.m.

7.2

CVSS3.1

CVE-2025-63911 -

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.

πŸ“… Published: March 3, 2026, midnight πŸ”„ Last Modified: March 5, 2026, 12:24 a.m.
Total resulsts: 348147
Page 1262 of 34,815
Β« previous page Β» next page
Filters