7.7

CVSS3.1

CVE-2025-30201 - Wazuh NetNTLMv2 Hash Theft In Multiple Centralized Configuration Capabilities

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various agent configuration settings, potentially leading …

📅 Published: Nov. 21, 2025, 6:17 p.m. 🔄 Last Modified: Feb. 26, 2026, 4:07 p.m.

7.4

CVSS3.1

CVE-2025-13132 - Dia: Increased Spoof Risk; Missing full screen toast

This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) appearing. Without this notification, users could potentially be misled about what site they were on if a malicious site renders a fake UI (like a fake address bar.)

📅 Published: Nov. 21, 2025, 5:55 p.m. 🔄 Last Modified: Nov. 25, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-64483 - Wazuh API – Agent Configuration Has Improper Access Control in Agent Enrollment Endpoint

Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent enrollment credentials through the /utils/configura…

📅 Published: Nov. 21, 2025, 5:55 p.m. 🔄 Last Modified: Feb. 6, 2026, 8:16 p.m.

0.0

CVE-2025-13511 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

📅 Published: Nov. 21, 2025, 5:30 p.m. 🔄 Last Modified: Nov. 24, 2025, 4:17 p.m.

7.7

CVSS4.0

CVE-2025-13470 - RNP 0.18.0 Vulnerable PKESK session keys

In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session Key (PKESK) packets to be left uninitialized except for zeroing, resulting in it always being an all-zero byte array. Any data encrypted using public-key encryption in this rel…

📅 Published: Nov. 21, 2025, 5:05 p.m. 🔄 Last Modified: Nov. 25, 2025, 10:16 p.m.

5.3

CVSS3.1

CVE-2025-12747 - Tainacan <= 1.0.0 - Unauthenticated Information Exposure

The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract potentially sensitive in…

📅 Published: Nov. 21, 2025, 4:28 p.m. 🔄 Last Modified: April 8, 2026, 5:21 p.m.

7.2

CVSS3.1

CVE-2025-12973 - S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.8 - Authenticated (Ed…

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function in all versions up to, and including, 1.7.8. This makes it possible for authenticated attackers, wi…

📅 Published: Nov. 21, 2025, 4:28 p.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

7.4

CVSS3.1

CVE-2025-13357 - Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. Thi…

📅 Published: Nov. 21, 2025, 3:02 p.m. 🔄 Last Modified: Dec. 10, 2025, 9 p.m.

10

CVSS3.1

CVE-2025-41115 - Incorrect privilege assignment

SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user i…

📅 Published: Nov. 21, 2025, 2:25 p.m. 🔄 Last Modified: April 9, 2026, 1:49 p.m.

4.3

CVSS3.1

CVE-2025-13432 - Terraform Enterprise state versions can be created by users with specific permissions without suffi…

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CV…

📅 Published: Nov. 21, 2025, 2:20 p.m. 🔄 Last Modified: Dec. 10, 2025, 9:02 p.m.
Total resulsts: 343825
Page 2399 of 34,383
« previous page » next page
Filters