5.1

CVSS3.1

CVE-2025-50361 -

Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593fe in the function main.cpp, which can lead to potential information leakage and crash.

📅 Published: Dec. 3, 2025, midnight 🔄 Last Modified: Dec. 18, 2025, 8:21 p.m.

5.1

CVSS3.1

CVE-2025-65842 -

The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local process without validating the client's identity, and its authorization logic incorrectly calls AuthorizationCopyRights…

📅 Published: Dec. 3, 2025, midnight 🔄 Last Modified: Dec. 18, 2025, 8:41 p.m.

4.9

CVSS3.1

CVE-2025-65955 - ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMag…

📅 Published: Dec. 2, 2025, 11:02 p.m. 🔄 Last Modified: Jan. 13, 2026, 2:50 a.m.

5.3

CVSS3.1

CVE-2025-55181 -

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends data to a std::vector per-loop iteration. This issue leads to unbounded memory growth and eventually ca…

📅 Published: Dec. 2, 2025, 10:13 p.m. 🔄 Last Modified: Dec. 19, 2025, 6:02 p.m.

0.0

CVE-2025-13933 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12500. Reason: This candidate is a reservation duplicate of CVE-2025-12500. Notes: All CVE users should reference CVE-2025-12500 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

📅 Published: Dec. 2, 2025, 9:59 p.m. 🔄 Last Modified: Feb. 18, 2026, 4:08 p.m.

7.8

CVSS3.1

CVE-2025-66476 - Vim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability

Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious executables placed in the current working directory for the current edited file. On Windows, when using cmd.exe as a shell, Vim resolves e…

📅 Published: Dec. 2, 2025, 9:49 p.m. 🔄 Last Modified: Feb. 26, 2026, 4:57 p.m.

8.7

CVSS4.0

CVE-2025-62575 - Mirion Medical EC2 Software NMIS BioDose Incorrect Permission Assignment for Critical Resource

NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.

📅 Published: Dec. 2, 2025, 9:11 p.m. 🔄 Last Modified: Jan. 2, 2026, 9:03 p.m.

8.4

CVSS4.0

CVE-2025-64778 - Mirion Medical EC2 Software NMIS BioDose Use of Hard-coded Credentials

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.

📅 Published: Dec. 2, 2025, 9:09 p.m. 🔄 Last Modified: Jan. 2, 2026, 8:57 p.m.

8.7

CVSS4.0

CVE-2025-61940 - Mirion Medical EC2 Software NMIS BioDose Use of Client-Side Authentication

NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest versi…

📅 Published: Dec. 2, 2025, 9:07 p.m. 🔄 Last Modified: Jan. 2, 2026, 9:03 p.m.

8.6

CVSS4.0

CVE-2025-64298 - Mirion Medical EC2 Software NMIS BioDose Incorrect Permission Assignment for Critical Resource

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configur…

📅 Published: Dec. 2, 2025, 9:05 p.m. 🔄 Last Modified: Jan. 2, 2026, 9:02 p.m.
Total resulsts: 343968
Page 2324 of 34,397
« previous page » next page
Filters