5.5

CVSS3.1

CVE-2025-40106 - comedi: fix divide-by-zero in comedi_buf_munge()

In the Linux kernel, the following vulnerability has been resolved: comedi: fix divide-by-zero in comedi_buf_munge() The comedi_buf_munge() function performs a modulo operation `async->munge_chan %= async->cmd.chanlist_len` without first checking if chanlist_len is zero. If a user program submits…

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

9.8

CVSS3.1

CVE-2025-57108 -

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files…

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 7:37 p.m.

7.5

CVSS3.1

CVE-2025-8849 - Denial of Service in danny-avila/librechat

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when exc…

πŸ“… Published: Oct. 30, 2025, 11:42 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 5:14 p.m.

10

CVSS3.1

CVE-2025-48983 -

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

πŸ“… Published: Oct. 30, 2025, 11:33 p.m. πŸ”„ Last Modified: Nov. 11, 2025, 2:07 a.m.

7.8

CVSS3.1

CVE-2025-48982 -

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.

πŸ“… Published: Oct. 30, 2025, 11:33 p.m. πŸ”„ Last Modified: Nov. 11, 2025, 2:05 a.m.

6.1

CVSS3.1

CVE-2025-27208 -

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context o…

πŸ“… Published: Oct. 30, 2025, 11:32 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:41 p.m.

8.8

CVSS3.1

CVE-2025-48984 -

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

πŸ“… Published: Oct. 30, 2025, 11:31 p.m. πŸ”„ Last Modified: Nov. 11, 2025, 2:08 a.m.

10

CVSS3.1

CVE-2025-52665 -

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.Β  A…

πŸ“… Published: Oct. 30, 2025, 11:30 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 2:51 p.m.

7.3

CVSS3.1

CVE-2025-52663 -

A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. Affected Product…

πŸ“… Published: Oct. 30, 2025, 11:30 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

6.5

CVSS3.0

CVE-2025-48980 -

In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method.

πŸ“… Published: Oct. 30, 2025, 11:29 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.
Total resulsts: 318385
Page 194 of 31,839
Β« previous page Β» next page
Filters