6.8

CVSS4.0

CVE-2025-27232 - Frontend arbitrary file read in oauth.authorize action

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

πŸ“… Published: Dec. 1, 2025, 12:55 p.m. πŸ”„ Last Modified: Feb. 6, 2026, 3:23 p.m.

9.1

CVSS3.1

CVE-2025-12106 -

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

πŸ“… Published: Dec. 1, 2025, 12:43 p.m. πŸ”„ Last Modified: Dec. 30, 2025, 2:52 p.m.

5.4

CVSS3.1

CVE-2025-13296 - CSRF in Tekrom Technology's T-Soft E-Commerce

Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Forgery.This issue affects T-Soft E-Commerce: through 28112025.

πŸ“… Published: Dec. 1, 2025, 11:51 a.m. πŸ”„ Last Modified: Dec. 1, 2025, 9:27 p.m.

5.9

CVSS3.1

CVE-2025-58408 - GPU DDK - KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling code

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free. The Use After Free common weakness enumeration was chosen as the stale data can include handles to resources in whic…

πŸ“… Published: Dec. 1, 2025, 11:16 a.m. πŸ”„ Last Modified: Dec. 29, 2025, 3:04 p.m.

4.8

CVSS4.0

CVE-2025-41070 - Reflected Cross-site Scripting (XSS) in Sanoma's Clickedu

Reflected Cross-site Scripting (XSS) vulnerability in Sanoma's Clickedu. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL in '/students/carpetes_varies.php'. This vulnerability can be exploited to steal sensitive user data, suc…

πŸ“… Published: Dec. 1, 2025, 10:40 a.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

5.1

CVSS3.1

CVE-2025-6349 - Mali GPU Kernel Driver allows improper GPU memory processing operations

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: …

πŸ“… Published: Dec. 1, 2025, 10:32 a.m. πŸ”„ Last Modified: Dec. 2, 2025, 2:43 p.m.

4

CVSS3.1

CVE-2025-8045 - Mali GPU Kernel Driver allows improper GPU processing operations

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r5…

πŸ“… Published: Dec. 1, 2025, 10:32 a.m. πŸ”„ Last Modified: Dec. 2, 2025, 2:44 p.m.

5.1

CVSS3.1

CVE-2025-2879 - Mali GPU Kernel Driver allows improper GPU processing operations

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU processing operations to expose sensitive data.This issue affects Valh…

πŸ“… Published: Dec. 1, 2025, 10:32 a.m. πŸ”„ Last Modified: Dec. 2, 2025, 2:43 p.m.

7.5

CVSS3.1

CVE-2025-59789 - Apache bRPC: Stack Exhaustion via Unbounded Recursion in JSON Parser

Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attackers to make the server crash via sending deep recursive json data. Root Cause: The bRPCΒ json2pb component uses rapidjson to parse json data from the network. The rapidjson parser …

πŸ“… Published: Dec. 1, 2025, 10:22 a.m. πŸ”„ Last Modified: Dec. 2, 2025, 2:39 p.m.

7.8

CVSS3.1

CVE-2025-41700 - CODESYS Development System - Deserialization of Untrusted Data

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

πŸ“… Published: Dec. 1, 2025, 10:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 3:35 p.m.
Total resulsts: 343919
Page 2344 of 34,392
Β« previous page Β» next page
Filters