8.8

CVSS3.1

CVE-2025-69784 -

A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an attacker-controlled DLL into high…

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

0.0

CVE-2025-69783 -

A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trusted process name (e.g., csrss.exe, edrsvc.exe, edrcon.exe). This allows unauthorized interaction with the OpenEDR kernel driver, granting access to privileged functionality such as…

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

0.0

CVE-2025-69902 -

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

5.4

CVSS3.1

CVE-2025-69693 - FFmpeg: out-of-bounds read in RV60 video decoder

Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from…

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 16, 2026, 9:16 p.m.

6.1

CVSS3.1

CVE-2025-57543 -

Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be rendered in the web UI when viewed by other users. This could potentially lead to user interface redress attacks or be escalated to XSS in certain contexts.

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

9.8

CVSS3.1

CVE-2025-69809 -

A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling arbitrary code execution via a crafted packet.

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

0.0

CVE-2025-68971 -

In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated with an issue or a release).

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

0.0

CVE-2025-50881 -

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, the script takes user-supplied input from the `action` URL parameter, performs insufficient validation, and incorporates this input into a str…

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

9.1

CVSS3.1

CVE-2025-69808 -

An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and cause a Denial of Service (DoS) via supplying a crafted packet.

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.

5.3

CVSS3.1

CVE-2025-69727 -

An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (index.js and composeUrlImgPhotoIndividu) allow the construction of direct URLs to user profile images based solely on predictable identifiers such as user IDs and names. Due to mi…

πŸ“… Published: March 16, 2026, midnight πŸ”„ Last Modified: March 17, 2026, 9:55 a.m.
Total resulsts: 338273
Page 21 of 33,828
Β« previous page Β» next page
Filters