8.7

CVSS3.1

CVE-2025-59271 - Redis Enterprise Elevation of Privilege Vulnerability

Redis Enterprise Elevation of Privilege Vulnerability

πŸ“… Published: Oct. 9, 2025, 9:04 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:04 p.m.

6.5

CVSS3.1

CVE-2025-59252 - M365 Copilot Spoofing Vulnerability

M365 Copilot Spoofing Vulnerability

πŸ“… Published: Oct. 9, 2025, 9:04 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:04 p.m.

8.7

CVSS3.1

CVE-2025-55321 - Azure Monitor Log Analytics Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an authorized attacker to perform spoofing over a network.

πŸ“… Published: Oct. 9, 2025, 9:04 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:04 p.m.

8.8

CVSS3.1

CVE-2025-59247 - Azure PlayFab Elevation of Privilege Vulnerability

Azure PlayFab Elevation of Privilege Vulnerability

πŸ“… Published: Oct. 9, 2025, 9:04 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:04 p.m.

9.8

CVSS3.1

CVE-2025-59246 - Azure Entra ID Elevation of Privilege Vulnerability

Azure Entra ID Elevation of Privilege Vulnerability

πŸ“… Published: Oct. 9, 2025, 9:04 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:04 p.m.

9.6

CVSS3.1

CVE-2025-59218 - Azure Entra ID Elevation of Privilege Vulnerability

Azure Entra ID Elevation of Privilege Vulnerability

πŸ“… Published: Oct. 9, 2025, 9:04 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:04 p.m.

6.9

CVSS4.0

CVE-2025-11558 - code-projects E-Commerce Website user_index_search.php sql injection

A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/user_index_search.php. Performing manipulation of the argument Search results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public a…

πŸ“… Published: Oct. 9, 2025, 9:02 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 2:17 p.m.

6.9

CVSS4.0

CVE-2025-11557 - projectworlds Gate Pass Management System add-pass.php sql injection

A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown processing of the file /add-pass.php. Such manipulation of the argument fullname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public…

πŸ“… Published: Oct. 9, 2025, 9:02 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 9:02 p.m.

6.3

CVSS4.0

CVE-2025-61783 - Python Social Auth - Django has unsafe account association

Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service d…

πŸ“… Published: Oct. 9, 2025, 8:57 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 8:57 p.m.

8.7

CVSS4.0

CVE-2025-61779 - Trustee's attestation-policy endpoint is not protected by admin autentication

Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key).…

πŸ“… Published: Oct. 9, 2025, 8:53 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 3:16 p.m.
Total resulsts: 313763
Page 24 of 31,377
Β« previous page Β» next page
Filters