7.8

CVSS3.1

CVE-2025-66411 - Coder logged sensitive objects unsanitized

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or …

πŸ“… Published: Dec. 3, 2025, 7:25 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 4:09 p.m.

5

CVSS3.1

CVE-2025-66406 - Improper Authorization Check for SSH Certificate Revocation

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH certificate revocation. This affects deployments configured with the SSHPOP provisioner. This vulnerability is fixed in 0.29.0.

πŸ“… Published: Dec. 3, 2025, 7:13 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

4.7

CVSS3.1

CVE-2025-13992 - chromium-browser: Side-channel information leakage in Navigation and Loading

Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: Dec. 3, 2025, 7:09 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 2:52 p.m.

7.5

CVSS3.1

CVE-2025-12819 - Untrusted search path in auth_query connection in PgBouncer

Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.

πŸ“… Published: Dec. 3, 2025, 7 p.m. πŸ”„ Last Modified: Dec. 27, 2025, 4:15 p.m.

6.3

CVSS4.0

CVE-2025-12084 - Quadratic complexity in node ID cache clearing

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

πŸ“… Published: Dec. 3, 2025, 6:55 p.m. πŸ”„ Last Modified: March 3, 2026, 2:41 p.m.

9.7

CVSS3.1

CVE-2025-66222 - DeepChat Cross-Site Scripting(XSS) escalate to Remote Code Execution(RCE)

DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC brid…

πŸ“… Published: Dec. 3, 2025, 6:34 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 3:37 p.m.

5

CVSS3.1

CVE-2025-66220 - Envoy’s TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certifica…

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null byte (\0) inside an OTHERNAME SAN value as valid matches.

πŸ“… Published: Dec. 3, 2025, 6:31 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 3:44 p.m.

7.2

CVSS4.0

CVE-2025-66208 - Configuration-Dependent RCE (OS Command Injection) in richdocumentscode proxy

Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online. In versions prior to 25.04.702, Collabora Online has a Configuration-Dependent RCE (OS Command Injection) in richdocumentscode proxy. Users of Nextcl…

πŸ“… Published: Dec. 3, 2025, 6:25 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 7:37 p.m.

8.8

CVSS3.1

CVE-2025-33208 -

NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploit of this vulnerability may lead to escalation of privileges, data tampering, denial of service, information disclosure.

πŸ“… Published: Dec. 3, 2025, 6:19 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 6:41 p.m.

8.7

CVSS4.0

CVE-2025-66032 - Claude Code Command Validation Bypass Allows Arbitrary Code Execution

Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability to add untrusted co…

πŸ“… Published: Dec. 3, 2025, 6:16 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 4:29 p.m.
Total resulsts: 343970
Page 2316 of 34,397
Β« previous page Β» next page
Filters