8.2

CVSS4.0

CVE-2025-68476 - KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Cr…

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerabilit…

📅 Published: Dec. 22, 2025, 9:35 p.m. 🔄 Last Modified: Dec. 23, 2025, 2:51 p.m.

7.5

CVSS3.1

CVE-2025-68475 - Fedify has ReDoS Vulnerability in HTML Parsing Regex

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/doclo…

📅 Published: Dec. 22, 2025, 9:31 p.m. 🔄 Last Modified: March 17, 2026, 7:39 p.m.

8.7

CVSS4.0

CVE-2025-34457 - wb2osz/direwolf <= 1.8.1 Stack-based Buffer Overflow DoS

wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 694c954, contain a stack-based buffer overflow vulnerability in the function kiss_rec_byte() located in src/kiss_frame.c. When processing crafted KISS frames that reach the maximum allowed frame length (MAX_KISS_LEN), the…

📅 Published: Dec. 22, 2025, 9:30 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

8.7

CVSS4.0

CVE-2025-34458 - wb2osz/direwolf <= 1.8.1 Reachable Assertion DoS

wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c. When processing a specially crafted AX.25 frame containing a MIC-E message with an empty o…

📅 Published: Dec. 22, 2025, 9:29 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

5.3

CVSS3.1

CVE-2025-68480 - Marshmallow has DoS in Schema.load(many)

Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a dispr…

📅 Published: Dec. 22, 2025, 9:20 p.m. 🔄 Last Modified: Dec. 23, 2025, 10:39 p.m.

6.5

CVSS3.1

CVE-2025-15033 - WooCommerce - Subscriber/Customer+ Order Data Disclosure

A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it ha…

📅 Published: Dec. 22, 2025, 6:57 p.m. 🔄 Last Modified: March 6, 2026, 9:09 a.m.

7

CVSS4.0

CVE-2025-10021 -

A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 2026.12. Static object `COdaMfcAppApp theApp` may access `OdString::kEmpty` before its initialization. Due to undefined initialization order of static objects across translation uni…

📅 Published: Dec. 22, 2025, 3:48 p.m. 🔄 Last Modified: Dec. 24, 2025, 11:53 a.m.

7.2

CVSS4.0

CVE-2025-61740 - Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG Origin Validation Error

Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-service condition or modify the configuration of the device.

📅 Published: Dec. 22, 2025, 2:32 p.m. 🔄 Last Modified: Dec. 23, 2025, 10:40 p.m.

7.2

CVSS4.0

CVE-2025-26379 - Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG use of Cryptographically Weak Pseudo-Rand…

Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.

📅 Published: Dec. 22, 2025, 2:21 p.m. 🔄 Last Modified: Dec. 23, 2025, 10:40 p.m.

7.3

CVSS3.1

CVE-2025-14018 - Unquoted Service Path in NetBT Consultancy's e-Fatura

Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating Configuration File Search Paths, Redirect Access to Libraries.This issue affects e-Fatura: before 1.2.15.

📅 Published: Dec. 22, 2025, 1:46 p.m. 🔄 Last Modified: Dec. 23, 2025, 2:51 p.m.
Total resulsts: 343975
Page 1958 of 34,398
« previous page » next page
Filters