7.2

CVSS3.1

CVE-2025-68385 - Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a method in Vega bypassing a previous Vega XSS miti…

πŸ“… Published: Dec. 18, 2025, 10:08 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 7:07 p.m.

6.5

CVSS3.1

CVE-2025-68384 - Elasticsearch Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

πŸ“… Published: Dec. 18, 2025, 10:04 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 5:45 p.m.

8.2

CVSS3.1

CVE-2025-64677 - Office Out-of-Box Experience Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: Dec. 18, 2025, 10:02 p.m. πŸ”„ Last Modified: April 16, 2026, 2:19 p.m.

7.2

CVSS3.1

CVE-2025-64676 - Microsoft Purview eDiscovery Remote Code Execution Vulnerability

'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

πŸ“… Published: Dec. 18, 2025, 10:02 p.m. πŸ”„ Last Modified: April 16, 2026, 2:19 p.m.

10

CVSS3.1

CVE-2025-65037 - Azure Container Apps Remote Code Execution Vulnerability

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

πŸ“… Published: Dec. 18, 2025, 10:02 p.m. πŸ”„ Last Modified: April 16, 2026, 2:19 p.m.

10

CVSS3.1

CVE-2025-65041 - Microsoft Partner Center Elevation of Privilege Vulnerability

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: Dec. 18, 2025, 10:02 p.m. πŸ”„ Last Modified: April 16, 2026, 2:19 p.m.

9.9

CVSS3.1

CVE-2025-64663 - Custom Question Answering Elevation of Privilege Vulnerability

Custom Question Answering Elevation of Privilege Vulnerability

πŸ“… Published: Dec. 18, 2025, 10:02 p.m. πŸ”„ Last Modified: April 16, 2026, 2:19 p.m.

3.1

CVSS3.1

CVE-2025-65046 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

πŸ“… Published: Dec. 18, 2025, 10:01 p.m. πŸ”„ Last Modified: April 16, 2026, 2:19 p.m.

6.5

CVSS3.1

CVE-2025-68383 - Filebeat Improper Validation of Specified Index, Position, or Offset in Input

Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog mes…

πŸ“… Published: Dec. 18, 2025, 10 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 5:59 p.m.

6.9

CVSS4.0

CVE-2025-13427 - Authentication Bypass in Dialogflow CX Messenger

An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact with restricted chat agents, gaining access to the agents' knowledge and the ability to trigger their intents, by manipulating initialization parameters or crafting specific API …

πŸ“… Published: Dec. 18, 2025, 9:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346120
Page 2198 of 34,612
Β« previous page Β» next page
Filters