1

CVSS4.0

CVE-2025-64725 - Weblate has improper validation upon invitation acceptance

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.

πŸ“… Published: Dec. 15, 2025, 8:21 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 9:25 p.m.

8.5

CVSS4.0

CVE-2025-59947 - NanoMQ has Buffer Overflow

NanoMQ is a messaging broker/bus for IoT Edge & SDV. Versions prior to 0.24.4 have a buffer overflow case while the PUBLISH packets trigger both shared subscription and vanila subscription. This is fixed in version 0.24.4. As a workaround, disable shared subscription.

πŸ“… Published: Dec. 15, 2025, 8:19 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 9:14 p.m.

5.9

CVSS3.1

CVE-2025-13489 - IBM DevOps Deploy is susceptible to a Cleartext Transmission of Sensitive Information

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

πŸ“… Published: Dec. 15, 2025, 7:51 p.m. πŸ”„ Last Modified: Dec. 26, 2025, 2:15 p.m.

8.6

CVSS4.0

CVE-2025-14503 - Overly Permissive Trust Policy in Harmonix on AWS EKS

An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via role assumption. The sample code for the EKS environment provisioning role is configured to trust the account root principal, which may enable any IAM p…

πŸ“… Published: Dec. 15, 2025, 7:45 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

6.5

CVSS3.1

CVE-2025-14148 - IBM DevOps Deploy is susceptible to a Insufficiently Protected Credentials vulnerability

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM API Token.

πŸ“… Published: Dec. 15, 2025, 7:43 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 5:53 p.m.

6.5

CVSS3.1

CVE-2025-12035 - Bluetooth: Integer Overflow in Bluetooth Classic (BR/EDR) L2CAP

An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for processing inbound BR/EDR L2CAP traffic.

πŸ“… Published: Dec. 15, 2025, 7:42 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 5:11 p.m.

5

CVSS3.1

CVE-2025-36360 - IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Insufficient Session Expiration…

IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly …

πŸ“… Published: Dec. 15, 2025, 7:38 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 6 p.m.

7

CVSS3.1

CVE-2025-14038 -

EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive data or possibly cause a denial-of-service by writing malformed data to certain gRPC endpoints. This flaw has been remedia…

πŸ“… Published: Dec. 15, 2025, 6:02 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:04 p.m.

0.0

CVE-2025-68128 -

reserved but not needed

πŸ“… Published: Dec. 15, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:47 p.m.

0.0

CVE-2025-68127 -

reserved but not needed

πŸ“… Published: Dec. 15, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:47 p.m.
Total resulsts: 343194
Page 2007 of 34,320
Β« previous page Β» next page
Filters