8

CVSS3.1

CVE-2025-20386 - Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade

In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets non-administrator users on the machine a…

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

2.4

CVSS3.1

CVE-2025-20385 - Stored Cross-Site scripting (XSS) through Anchor Tag "href" in Navigation Bar Collections in Splunk…

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.6, 10.0.2503.7, and 9.3.2411.117, a user who holds a role with a high privilege capability `admin_all_objects` could craft a malicious payload through the href attribute of an an…

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 6:13 p.m.

5.4

CVSS3.1

CVE-2025-20381 - SPL commands allowlist controls bypass in Splunk MCP Server app through "run_splunk_query" MCP tool

In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command allowlist controls in MCP by embedding SPL commands as sub-searches, leading to unauthorized actions beyond the intended MCP restrictions.

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

3.5

CVSS3.1

CVE-2025-20382 - URL validation bypass through Views Dashboard in Splunk Enterprise

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a views dashboard with a custom background using the …

πŸ“… Published: Dec. 3, 2025, 5 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 6:33 p.m.

7.5

CVSS3.1

CVE-2024-3884 - Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows…

πŸ“… Published: Dec. 3, 2025, 4:50 p.m. πŸ”„ Last Modified: April 1, 2026, 1:32 p.m.

9.3

CVSS4.0

CVE-2025-34319 - TOTOLINK N300RT <= V2.1.8-B20201030.1539 Boa formWsc RCE

TOTOLINK N300RT wireless router firmware versions prior toΒ V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vulnerability in the Boa formWsc handling functionality. An unauthenticated attacker can send specially crafted requests to trigger command execution via…

πŸ“… Published: Dec. 3, 2025, 4:49 p.m. πŸ”„ Last Modified: March 5, 2026, 12:03 p.m.

7.5

CVSS3.1

CVE-2024-32643 - Masa CMS vulnerable to authentication bypass with /tag/

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS will render the page regardless of group restrictions. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.

πŸ“… Published: Dec. 3, 2025, 4:43 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 3:37 p.m.

8.8

CVSS3.1

CVE-2024-32642 - Host header poisoning allows account takeover via password reset email

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.

πŸ“… Published: Dec. 3, 2025, 4:37 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 3:36 p.m.

5.4

CVSS4.0

CVE-2025-13492 - HP Image Assistant - Potential Escalation of Privilege

A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerability could potentially allow a local attacker to escalate privileges via a race condition when installing packages.

πŸ“… Published: Dec. 3, 2025, 4:33 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

9.8

CVSS3.1

CVE-2024-32641 - Masa CMS Vulnerable to Pre-Auth RCE via JSON API

Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluate…

πŸ“… Published: Dec. 3, 2025, 4:26 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 2:47 p.m.
Total resulsts: 343980
Page 2319 of 34,398
Β« previous page Β» next page
Filters