0.0

CVE-2025-12977 - CVE-2025-12977

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid t…

πŸ“… Published: Nov. 24, 2025, 2:40 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 2:40 p.m.

0.0

CVE-2025-12970 - CVE-2025-12970

The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating length. An attacker who can create containers or control container names, can supply a long name that overflows the buffer, leading to process crash or arbitrary c…

πŸ“… Published: Nov. 24, 2025, 2:39 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 2:40 p.m.

9.3

CVSS4.0

CVE-2025-11921 - iStat Menus 7.10.4 - Local Privilege Escalation

iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.

πŸ“… Published: Nov. 24, 2025, 2:22 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 2:22 p.m.

0.0

CVE-2025-65998 - Apache Syncope: Default AES key used for internal password encryption

Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option. When AES is configured, the default key value, hard-coded in the source code, is always used. This allows a malicious attacker, once obtained acce…

πŸ“… Published: Nov. 24, 2025, 1:47 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 1:47 p.m.

0.0

CVE-2025-40212 - nfsd: fix refcount leak in nfsd_set_fh_dentry()

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nfsd exports a "pseudo root filesystem" which is used by NFSv4 to find the various exported filesystems using LOOKUP requests from a known root filehandle. NFSv3 uses the MOUNT pro…

πŸ“… Published: Nov. 24, 2025, 1:04 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 1:04 p.m.

0.0

CVE-2025-12628 - WP 2FA < 3.0.0 - Second Factor Bypass

The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing them

πŸ“… Published: Nov. 24, 2025, 12:58 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 12:58 p.m.

6.9

CVSS4.0

CVE-2025-41017 - Multiple vulnerabilities in DFUSION by Davantis

Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve perspective parameters from security camera settings by accessing β€œ/cameras/<CAMERA_ID>/perspective”.

πŸ“… Published: Nov. 24, 2025, 12:20 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 12:20 p.m.

8.7

CVSS4.0

CVE-2025-41016 - Multiple vulnerabilities in DFUSION by Davantis

Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to β€œ/alarms/<ALARM_ID>/<MEDIA>”, where the β€œMEDIA” parameter can take the value of β€œsnapshot” or β€œvideo.mp4”. These media files …

πŸ“… Published: Nov. 24, 2025, 12:18 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 12:18 p.m.

7.7

CVSS4.0

CVE-2025-12741 - Arbitrary File Write in Denodo dialect of Looker allows Remote Code Execution

A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malicious command. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances.Β No user a…

πŸ“… Published: Nov. 24, 2025, 11:35 a.m. πŸ”„ Last Modified: Nov. 24, 2025, 11:35 a.m.

7.7

CVSS4.0

CVE-2025-12740 - Remote Command Execution in Looker via IBM DB2 JDBC drive

A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a malicious command, due to inadequate filtering of the driver's parameters. Looker-hosted and Self-hosted were found to be vulnerable. This issue has al…

πŸ“… Published: Nov. 24, 2025, 11:30 a.m. πŸ”„ Last Modified: Nov. 24, 2025, 11:30 a.m.
Total resulsts: 319244
Page 2 of 31,925
Β« previous page Β» next page
Filters