0.0

CVE-2025-38693 - media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read…

In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar In w7090p_tuner_write_serpar, msg is controlled by user. When msg[0].buf is null and msg[0].len is zero, former checks on …

📅 Published: Sept. 4, 2025, 3:32 p.m. 🔄 Last Modified: Sept. 4, 2025, 4:15 p.m.

6.5

CVSS3.1

CVE-2025-25048 - IBM Jazz Foundation path traversal

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.

📅 Published: Sept. 4, 2025, 3:06 p.m. 🔄 Last Modified: Sept. 4, 2025, 3:35 p.m.

6.1

CVSS3.1

CVE-2024-43184 - IBM Jazz Foundation cross-site scripting

IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potent…

📅 Published: Sept. 4, 2025, 3:04 p.m. 🔄 Last Modified: Sept. 4, 2025, 5:39 p.m.

2.7

CVSS3.1

CVE-2025-2667 - IBM Sterling B2B Integrator information disclosure

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose sensitive system information about the server to a privileged user that could aid in further attacks against the syste…

📅 Published: Sept. 4, 2025, 2:45 p.m. 🔄 Last Modified: Sept. 4, 2025, 3:35 p.m.

4.8

CVSS3.1

CVE-2025-2694 - IBM Sterling B2B Integrator cross-site scripting

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI t…

📅 Published: Sept. 4, 2025, 2:43 p.m. 🔄 Last Modified: Sept. 4, 2025, 3:35 p.m.

4.7

CVSS4.0

CVE-2025-6785 - Tesla Model 3 Physical CAN Bus Injection

Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle.  Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). …

📅 Published: Sept. 4, 2025, 2:13 p.m. 🔄 Last Modified: Sept. 4, 2025, 3:35 p.m.

9.4

CVSS4.0

CVE-2025-8311 -

dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint. This endpoint uses the sites query parameter, which accepts a comma-separated list of site identifiers or keys. The vulnerability was triggered via the sites parameter, whic…

📅 Published: Sept. 4, 2025, 2:12 p.m. 🔄 Last Modified: Sept. 11, 2025, 2:24 p.m.

8.4

CVSS3.1

CVE-2025-7388 - Authenticated Command Injection via configuration parameter manipulation in exposed RMI interface

It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS commands under the delegated authority of the AdminServer process.  An RMI interface permitted manipulation of a configuration property…

📅 Published: Sept. 4, 2025, 1:01 p.m. 🔄 Last Modified: Sept. 4, 2025, 8:12 p.m.

9.3

CVSS4.0

CVE-2025-7385 - SQL Injection in GOV CMS

Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected.

📅 Published: Sept. 4, 2025, 12:05 p.m. 🔄 Last Modified: Sept. 4, 2025, 3:35 p.m.

4.8

CVSS4.0

CVE-2025-41063 - Reflected Cross-Site Scripting vulnerability in appRain CMF

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 's' parameter in /apprain/developer/debug-log/db.

📅 Published: Sept. 4, 2025, 11:16 a.m. 🔄 Last Modified: Sept. 4, 2025, 5:50 p.m.
Total resulsts: 309462
Page 128 of 30,947
« previous page » next page
Filters