7.8

CVSS3.1

CVE-2025-43939 -

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privi…

πŸ“… Published: Oct. 30, 2025, 2:10 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:57 p.m.

7.8

CVSS3.1

CVE-2025-43940 -

Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privi…

πŸ“… Published: Oct. 30, 2025, 2:05 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:58 p.m.

7.2

CVSS3.1

CVE-2025-43941 -

Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary command with root privileges. T…

πŸ“… Published: Oct. 30, 2025, 1:57 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:58 p.m.

5.1

CVSS4.0

CVE-2025-10348 - Stored Cross-Site Scripting in URVE Smart Office

URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without a…

πŸ“… Published: Oct. 30, 2025, 1 p.m. πŸ”„ Last Modified: Oct. 31, 2025, 10:14 a.m.

5.1

CVSS4.0

CVE-2025-10317 - Multiple Cross-Site Request Forgery in Quick.Cart

Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious product with content defined by the attacker. This software does not i…

πŸ“… Published: Oct. 30, 2025, 11:48 a.m. πŸ”„ Last Modified: Oct. 31, 2025, 10:14 a.m.

9.3

CVSS4.0

CVE-2025-53883 - spacewalk-java has various XSS issues on search page

A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run arbitrary javascript via a reflected XSS issue in the search fields.This issue affects Container suse/manager/5.0/x86_64/server:latest: from ? before 5.0.28-150600.3.36.8; SUSE Mana…

πŸ“… Published: Oct. 30, 2025, 10:50 a.m. πŸ”„ Last Modified: Oct. 31, 2025, 3:55 a.m.

8.5

CVSS4.0

CVE-2025-39663 - Cross Site Scripting through compromised remote site

Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).

πŸ“… Published: Oct. 30, 2025, 10:43 a.m. πŸ”„ Last Modified: Nov. 7, 2025, 4:15 p.m.

8.7

CVSS4.0

CVE-2025-53880 - susemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversal

A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of …

πŸ“… Published: Oct. 30, 2025, 10:31 a.m. πŸ”„ Last Modified: Oct. 31, 2025, 3:55 a.m.

0.0

CVE-2025-40094 - usb: gadget: f_acm: Refactor bind path to use __free()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_acm: Refactor bind path to use __free() After an bind/unbind cycle, the acm->notify_req is left stale. If a subsequent bind fails, the unified error label attempts to free this stale request, leading to a NULL poin…

πŸ“… Published: Oct. 30, 2025, 9:48 a.m. πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.

6.5

CVSS3.1

CVE-2025-54471 - NeuVector is shipping cryptographic material into its binary

NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was replaced with the secret key value and used to encrypt sensitive configurations when NeuVector stores the data.

πŸ“… Published: Oct. 30, 2025, 9:45 a.m. πŸ”„ Last Modified: Oct. 30, 2025, 3:03 p.m.
Total resulsts: 317640
Page 134 of 31,764
Β« previous page Β» next page
Filters