8.1

CVSS3.1

CVE-2025-12805 - Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy

A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user i…

📅 Published: Dec. 31, 2025, 11:59 p.m. 🔄 Last Modified: March 31, 2026, 3:55 a.m.

3.4

CVSS3.1

CVE-2025-69412 -

KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.

📅 Published: Dec. 31, 2025, 11:20 p.m. 🔄 Last Modified: Jan. 2, 2026, 4:45 p.m.

6.1

CVSS3.1

CVE-2025-67711 - Reflected XSS vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:18 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:03 p.m.

6.1

CVSS3.1

CVE-2025-67710 - Stored XSS vulnerability in ArcGIS Server

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:18 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:04 p.m.

6.1

CVSS3.1

CVE-2025-67709 - There is a cross site scripting issue in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:17 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:04 p.m.

6.1

CVSS3.1

CVE-2025-67708 - Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:17 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:04 p.m.

5.6

CVSS3.1

CVE-2025-67707 - Unvalidated File Upload vulnerability in ArcGIS Server.

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture enforces controls that restrict uploaded …

📅 Published: Dec. 31, 2025, 10:16 p.m. 🔄 Last Modified: Feb. 20, 2026, 2:48 p.m.

5.6

CVSS3.1

CVE-2025-67706 - Unvalidated File Upload vulnerability in ArcGIS Server.

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the server’s architecture enforces controls that restrict uploaded …

📅 Published: Dec. 31, 2025, 10:15 p.m. 🔄 Last Modified: Feb. 19, 2026, 9:29 p.m.

6.1

CVSS3.1

CVE-2025-67705 - Reflected XSS vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:15 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:09 p.m.

6.1

CVSS3.1

CVE-2025-67704 - Stored XSS vulnerability in ArcGIS Server.

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.

📅 Published: Dec. 31, 2025, 10:14 p.m. 🔄 Last Modified: Jan. 6, 2026, 7:14 p.m.
Total resulsts: 343968
Page 1795 of 34,397
« previous page » next page
Filters