1.8

CVSS4.0

CVE-2025-6075 - Quadratic complexity in os.path.expandvars() with user-controlled template

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

πŸ“… Published: Oct. 31, 2025, 4:41 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

6.9

CVSS4.0

CVE-2025-12554 - Missing Security Headers

Missing Security Headers.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 31, 2025, 3:52 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:48 p.m.

8.4

CVSS3.1

CVE-2025-12509 - Scripts for the module Global_Shipping executable on BRAIN2 Server

On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator rights.

πŸ“… Published: Oct. 31, 2025, 3:51 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.4

CVSS3.1

CVE-2025-12508 - Unencrypted communication to Active Directory services

When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confidentiality.

πŸ“… Published: Oct. 31, 2025, 3:49 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.8

CVSS3.1

CVE-2025-12507 - Insecure service configuration – unquoted path

The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.

πŸ“… Published: Oct. 31, 2025, 3:48 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

10

CVSS4.0

CVE-2025-12553 - Server Certificate Verification Disabled

Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 31, 2025, 3:48 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:48 p.m.

6.9

CVSS4.0

CVE-2025-12552 - Insufficient Password Policy

Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 31, 2025, 3:43 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:49 p.m.

7.2

CVSS4.0

CVE-2025-12357 - International Standards Organization ISO 15118-2 Improper Restriction of Communication Channel to I…

By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable wirelessly, within clos…

πŸ“… Published: Oct. 31, 2025, 3:33 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.1

CVSS3.1

CVE-2025-64168 - Agno session state overwrites between different sessions/users

Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent or Team during run or arun calls, a race condition can occur, causing a session_state to be assigned and persisted to the incorrect session. This may…

πŸ“… Published: Oct. 31, 2025, 2:58 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

9.2

CVSS4.0

CVE-2025-64385 - INCORRECT SECURITY VALIDATION IN SENDING UDP FRAMES

The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the manufacturer’s software. Using the manufacturer's software, the device can be configured via UDP. Analyzing this communication, it has been observed that any aspect of the initial…

πŸ“… Published: Oct. 31, 2025, 2:23 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.
Total resulsts: 318232
Page 170 of 31,824
Β« previous page Β» next page
Filters