6.9

CVSS4.0

CVE-2025-34238 - Advantech WebAccess/VPN < 1.1.5 Path Traversal via AjaxStandaloneVpnClientsController.ajaxDownloadR…

Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() that allows an authenticated network administrator to cause the application to read and return the contents of arbitrary files the web …

📅 Published: Nov. 6, 2025, 7:43 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.

6.3

CVSS4.0

CVE-2025-34237 - Advantech WebAccess/VPN < 1.1.5 Stored XSS via StandaloneVpnClientsController.addStandaloneVpnClien…

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the…

📅 Published: Nov. 6, 2025, 7:40 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

6.2

CVSS4.0

CVE-2025-34236 - Advantech WebAccess/VPN < 1.1.5 Stored XSS via NetworksController.addNetworkAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's b…

📅 Published: Nov. 6, 2025, 7:39 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

6.7

CVSS3.1

CVE-2025-22397 -

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain an Improper Limitation of a Pathname to a Restricted Directory ('Pat…

📅 Published: Nov. 6, 2025, 6:46 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

7.3

CVSS3.1

CVE-2024-25621 - containerd affected by a local privilege escalation via wide permissions on CRI directory

containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc…

📅 Published: Nov. 6, 2025, 6:36 p.m. 🔄 Last Modified: Nov. 6, 2025, 8:38 p.m.

5.3

CVSS4.0

CVE-2025-12815 -

An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. To mitiga…

📅 Published: Nov. 6, 2025, 5:10 p.m. 🔄 Last Modified: Nov. 6, 2025, 8:38 p.m.

7.8

CVSS3.1

CVE-2025-10885 - Privilege Escalation Vulnerability

A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM.

📅 Published: Nov. 6, 2025, 5:01 p.m. 🔄 Last Modified: Nov. 8, 2025, 4:55 a.m.

8.8

CVSS3.1

CVE-2025-12485 -

Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step. This issue affects the following versions …

📅 Published: Nov. 6, 2025, 4:37 p.m. 🔄 Last Modified: Nov. 7, 2025, 2:15 p.m.

6.5

CVSS3.1

CVE-2025-12808 -

Improper access control in Devolutions Server 2025.3.5.0 and earlier allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure.

📅 Published: Nov. 6, 2025, 4:36 p.m. 🔄 Last Modified: Nov. 7, 2025, 10:54 a.m.

8.1

CVSS3.1

CVE-2025-64287 - WordPress Alloggio - Hotel Booking Theme theme <= 1.8 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Alloggio - Hotel Booking alloggio allows PHP Local File Inclusion.This issue affects Alloggio - Hotel Booking: from n/a through <= 1.8.

📅 Published: Nov. 6, 2025, 3:56 p.m. 🔄 Last Modified: Nov. 6, 2025, 8:38 p.m.
Total resulsts: 317431
Page 22 of 31,744
« previous page » next page
Filters