6.5

CVSS3.1

CVE-2025-12653 - Authentication Bypass by Spoofing in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.

πŸ“… Published: Nov. 26, 2025, 7:46 p.m. πŸ”„ Last Modified: Dec. 10, 2025, 11:15 p.m.

2

CVSS3.1

CVE-2025-13611 - Insertion of Sensitive Information into Log File in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

πŸ“… Published: Nov. 26, 2025, 7:45 p.m. πŸ”„ Last Modified: March 31, 2026, 11:46 a.m.

6.9

CVSS4.0

CVE-2025-66028 - OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation

OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a parameter called isMasterAdmin. By intercepting and modifying thi…

πŸ“… Published: Nov. 26, 2025, 6:11 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 1:57 p.m.

8.8

CVSS4.0

CVE-2025-65966 - OneUptime Unauthorized User Creation via API

OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in version 9.1.0.

πŸ“… Published: Nov. 26, 2025, 6:10 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 2:05 p.m.

2.7

CVSS3.1

CVE-2025-20373 - Sensitive Information Disclosure in β€œ_internalβ€œ index through Splunk Add-On for Palo Alto Networks

In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition of new β€œData Security Accountsβ€œ. The vulnerability would require either local access to the log files or administrative access to internal indexes…

πŸ“… Published: Nov. 26, 2025, 5:59 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

9.3

CVSS4.0

CVE-2025-64130 - Zenitel TCIV-3+ Cross-site Scripting

Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.

πŸ“… Published: Nov. 26, 2025, 5:55 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

7

CVSS4.0

CVE-2025-64129 - Zenitel TCIV-3+ Out-of-bounds Write

Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the device.

πŸ“… Published: Nov. 26, 2025, 5:54 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

6.5

CVSS3.1

CVE-2021-4472 - Python-mistralclient: mistral-dashboard: local file inclusion through the 'create workbook' feature

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.

πŸ“… Published: Nov. 26, 2025, 5:51 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

10

CVSS4.0

CVE-2025-64128 - Zenitel TCIV-3+ OS Command Injection

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to append arbitrary data. This could allow an unauthenticated attacker to inject arbitrary commands.

πŸ“… Published: Nov. 26, 2025, 5:51 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

10

CVSS4.0

CVE-2025-64127 - Zenitel TCIV-3+ OS Command Injection

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute arbitrary commands remotely.

πŸ“… Published: Nov. 26, 2025, 5:50 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.
Total resulsts: 343746
Page 2352 of 34,375
Β« previous page Β» next page
Filters