5.9

CVSS4.0

CVE-2025-8307 - Recoverable passwords in Asseco Infomedica Plus

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedd…

πŸ“… Published: Jan. 8, 2026, 1:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-8306 - Improper Access Control in Asseco Infomedica Plus

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. A low privileged user is able to obtain encoded passwords of all other accounts (including main administrator) due to lack of granularity in access control.Β  Chained exploita…

πŸ“… Published: Jan. 8, 2026, 1:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-69260 -

A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.

πŸ“… Published: Jan. 8, 2026, 12:50 p.m. πŸ”„ Last Modified: Jan. 15, 2026, 7:11 p.m.

7.5

CVSS3.1

CVE-2025-69259 -

A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability..

πŸ“… Published: Jan. 8, 2026, 12:50 p.m. πŸ”„ Last Modified: Jan. 15, 2026, 7:14 p.m.

9.8

CVSS3.1

CVE-2025-69258 -

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

πŸ“… Published: Jan. 8, 2026, 12:50 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

9.8

CVSS3.1

CVE-2025-62877 - Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer

Projects using the SUSE Virtualization (Harvester) environment mayΒ expose the OS default ssh login passwordΒ Β if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism …

πŸ“… Published: Jan. 8, 2026, 12:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-66001 - NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.

πŸ“… Published: Jan. 8, 2026, 10:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2025-14459 - Virt-cdi-controller: unauthorized pvc cloning via dataimportcron

A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism.

πŸ“… Published: Jan. 8, 2026, 10:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2025-15224 - libssh key passphrase bypass without agent set

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

πŸ“… Published: Jan. 8, 2026, 10:08 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 2:47 p.m.

5.3

CVSS3.1

CVE-2025-15079 - libssh global known_hosts override

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.

πŸ“… Published: Jan. 8, 2026, 10:08 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 2:50 p.m.
Total resulsts: 346616
Page 1970 of 34,662
Β« previous page Β» next page
Filters