4.8

CVSS3.1

CVE-2025-55059 -

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

πŸ“… Published: Nov. 17, 2025, 5:36 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 4:32 p.m.

4.5

CVSS3.1

CVE-2025-55058 -

CWE-20 Improper Input Validation

πŸ“… Published: Nov. 17, 2025, 5:33 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 3:56 p.m.

4.5

CVSS3.1

CVE-2025-55057 -

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

πŸ“… Published: Nov. 17, 2025, 5:31 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 3:49 p.m.

7.5

CVSS3.1

CVE-2025-64756 - glob CLI: Command injection via -c/--cmd executes matches with shell:true

Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command injection vulnerability in its -c/--cmd option that allows arbitrary command execution when processing files with malicious names. When glob -c <comm…

πŸ“… Published: Nov. 17, 2025, 5:29 p.m. πŸ”„ Last Modified: Dec. 2, 2025, 7:34 p.m.

4.8

CVSS3.1

CVE-2025-55056 -

Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

πŸ“… Published: Nov. 17, 2025, 5:28 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 3:47 p.m.

6.8

CVSS3.1

CVE-2025-55055 -

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

πŸ“… Published: Nov. 17, 2025, 5:25 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 3:46 p.m.

4.8

CVSS3.1

CVE-2025-64758 - @dependencytrack/frontend Vulnerable to Persistent Cross-Site-Scripting via Welcome Message

@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Since version 4.12.0, Dependency-Track users with the SYSTEM_CONFIGURATION permission…

πŸ“… Published: Nov. 17, 2025, 5:24 p.m. πŸ”„ Last Modified: Nov. 18, 2025, 2:06 p.m.

6.9

CVSS4.0

CVE-2025-64342 - ESF-IDF's ESP32 Bluetooth Controller Has an Invalid Access Address Vulnerability

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it receives a connection request containing an invalid Access Address (AA) of 0x00000000 or 0xFFFFFFFF, advertising may stop unexpectedly. In this case, the controller may incorrectly …

πŸ“… Published: Nov. 17, 2025, 5:21 p.m. πŸ”„ Last Modified: Nov. 18, 2025, 2:06 p.m.

7.4

CVSS3.1

CVE-2025-58407 - GPU DDK - TOCTOU bug affecting psFWMemContext->uiPageCatBaseRegSet

Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.

πŸ“… Published: Nov. 17, 2025, 5:18 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 5:13 p.m.

6.9

CVSS4.0

CVE-2025-13291 - Campcodes Supplier Management System confirm_order.php sql injection

A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufacturer/confirm_order.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be…

πŸ“… Published: Nov. 17, 2025, 5:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.
Total resulsts: 343194
Page 2394 of 34,320
Β« previous page Β» next page
Filters