4.3

CVSS3.1

CVE-2025-46388 -

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

πŸ“… Published: Aug. 6, 2025, 10:47 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

8.8

CVSS3.1

CVE-2025-46387 -

CWE-639 Authorization Bypass Through User-Controlled Key

πŸ“… Published: Aug. 6, 2025, 10:43 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

8.8

CVSS3.1

CVE-2025-46386 -

CWE-639 Authorization Bypass Through User-Controlled Key

πŸ“… Published: Aug. 6, 2025, 10:14 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

6.5

CVSS3.1

CVE-2025-6013 - Vault LDAP MFA Enforcement Bypass When Using Username As Alias

Vault and Vault Enterprise’s (β€œVault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and …

πŸ“… Published: Aug. 6, 2025, 10:06 a.m. πŸ”„ Last Modified: Aug. 7, 2025, 3:55 a.m.

9.3

CVSS4.0

CVE-2025-22470 -

CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrary Lua script may be executed on the system with the root privilege.

πŸ“… Published: Aug. 6, 2025, 9:52 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

6.9

CVSS4.0

CVE-2025-22469 -

OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1. An arbitrary OS command may be executed on the system with a certain non-administrative user privilege.

πŸ“… Published: Aug. 6, 2025, 9:52 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

8.7

CVSS4.0

CVE-2025-7771 - Code Execution / Escalation of Privileges in ThrottleStop

ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrar…

πŸ“… Published: Aug. 6, 2025, 9:35 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:25 p.m.

5.3

CVSS3.1

CVE-2025-8620 - GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id.

πŸ“… Published: Aug. 6, 2025, 9:22 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

3.7

CVSS3.1

CVE-2025-8556 - Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results

A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

πŸ“… Published: Aug. 6, 2025, 8:48 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:24 p.m.

5.1

CVSS4.0

CVE-2025-7202 - Cross-Site Request Forgery (CSRF) allowed remote control of Elgato Key Lights

A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.

πŸ“… Published: Aug. 6, 2025, 8:28 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.
Total resulsts: 304618
Page 17 of 30,462
Β« previous page Β» next page
Filters