6.1

CVSS3.0

CVE-2025-55124 -

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

πŸ“… Published: Nov. 20, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

7.1

CVSS3.0

CVE-2025-52670 -

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

πŸ“… Published: Nov. 20, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

3.5

CVSS3.0

CVE-2025-52667 -

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

πŸ“… Published: Nov. 20, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.5

CVSS3.0

CVE-2025-55126 -

HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign names being the vector for the stored XSS

πŸ“… Published: Nov. 20, 2025, 7:07 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

5.4

CVSS3.1

CVE-2025-55127 -

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the…

πŸ“… Published: Nov. 20, 2025, 7:07 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.5

CVSS3.0

CVE-2025-55128 -

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an uncontrolled resource consumption vulnerability in the β€œuserlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page, potentially leading to a denial of service

πŸ“… Published: Nov. 20, 2025, 7:06 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

9.4

CVSS4.0

CVE-2025-10571 - ABB Ability Edgenius Authentication Bypass

Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects ABB Ability Edgenius: 3.2.0.0, 3.2.1.1.

πŸ“… Published: Nov. 20, 2025, 6:06 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

3.3

CVSS3.1

CVE-2025-64524 - CUPS rastertopclx Filter Vulnerable to Heap Buffer Overflow Leading to Potential Arbitrary Code Exe…

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and prior, a heap-buffer-overflow vulnerability in the rastertopclx filter causes the program to crash with a segmentation fault whe…

πŸ“… Published: Nov. 20, 2025, 6:05 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

8.9

CVSS4.0

CVE-2025-64428 - DataEase DB2 JNDI Vulnerability

Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbaname, and iiopname schemes. The vulnerability has been fixed i…

πŸ“… Published: Nov. 20, 2025, 5:07 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.9

CVSS4.0

CVE-2025-64185 - Open OnDemand RPM packages create world writable locations

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.

πŸ“… Published: Nov. 20, 2025, 4:58 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319173
Page 24 of 31,918
Β« previous page Β» next page
Filters