6.5

CVSS3.1

CVE-2025-14148 - IBM DevOps Deploy is susceptible to a Insufficiently Protected Credentials vulnerability

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM API Token.

πŸ“… Published: Dec. 15, 2025, 7:43 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 5:53 p.m.

6.5

CVSS3.1

CVE-2025-12035 - Bluetooth: Integer Overflow in Bluetooth Classic (BR/EDR) L2CAP

An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for processing inbound BR/EDR L2CAP traffic.

πŸ“… Published: Dec. 15, 2025, 7:42 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 5:11 p.m.

5

CVSS3.1

CVE-2025-36360 - IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Insufficient Session Expiration…

IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly …

πŸ“… Published: Dec. 15, 2025, 7:38 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 6 p.m.

7

CVSS3.1

CVE-2025-14038 -

EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive data or possibly cause a denial-of-service by writing malformed data to certain gRPC endpoints. This flaw has been remedia…

πŸ“… Published: Dec. 15, 2025, 6:02 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:04 p.m.

0.0

CVE-2025-68128 -

reserved but not needed

πŸ“… Published: Dec. 15, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:47 p.m.

0.0

CVE-2025-68127 -

reserved but not needed

πŸ“… Published: Dec. 15, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:47 p.m.

0.0

CVE-2025-68124 -

reserved but not needed

πŸ“… Published: Dec. 15, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:47 p.m.

0.0

CVE-2025-68126 -

reserved but not needed

πŸ“… Published: Dec. 15, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:47 p.m.

0.0

CVE-2025-68125 -

reserved but not needed

πŸ“… Published: Dec. 15, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:47 p.m.

6.4

CVSS3.1

CVE-2025-14387 - LearnPress – WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scriptin…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,…

πŸ“… Published: Dec. 15, 2025, 3:30 p.m. πŸ”„ Last Modified: April 8, 2026, 5:32 p.m.
Total resulsts: 343920
Page 2080 of 34,392
Β« previous page Β» next page
Filters