2.1

CVSS4.0

CVE-2025-11934 - Improper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerify

Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm used. For example when a client sends ECDSA P521 as the supported signature algorithm the server previously coโ€ฆ

๐Ÿ“… Published: Nov. 21, 2025, 10:12 p.m. ๐Ÿ”„ Last Modified: Dec. 8, 2025, 3:48 p.m.

8.1

CVSS3.1

CVE-2025-65946 - Roo Code is Vulnerable to Potential Remote Code Execution via zsh Command Validation Bug

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue has been patched in version 3.26.7.

๐Ÿ“… Published: Nov. 21, 2025, 10:11 p.m. ๐Ÿ”„ Last Modified: Dec. 4, 2025, 4:02 p.m.

6.3

CVSS4.0

CVE-2025-11935 - Forward Secrecy Violation in WolfSSL TLS 1.3

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when aย server responded to a ClientHello containing psk_dhe_ke without a key_share exteโ€ฆ

๐Ÿ“… Published: Nov. 21, 2025, 10:04 p.m. ๐Ÿ”„ Last Modified: Dec. 8, 2025, 3:49 p.m.

2.9

CVSS4.0

CVE-2025-65111 - SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplโ€ฆ

SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one sโ€ฆ

๐Ÿ“… Published: Nov. 21, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: Dec. 31, 2025, 1:41 p.m.

8.5

CVSS4.0

CVE-2025-65109 - Minder does not sandbox http.send in Rego programs

Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have accessโ€ฆ

๐Ÿ“… Published: Nov. 21, 2025, 9:56 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 10:16 p.m.

10

CVSS3.1

CVE-2025-65108 - md-to-pdf is vulnerable to arbitrary JavaScript code execution when parsing front matter

md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of โ€ฆ

๐Ÿ“… Published: Nov. 21, 2025, 9:52 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-65107 - Langfuse SSO Account Takeover via CSRF or phishing attack

Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations without an explicit AUTH_<PROVIDER>_CHECK setting, a potential account takeover may happen if an authenticated user is maโ€ฆ

๐Ÿ“… Published: Nov. 21, 2025, 9:49 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 3:24 p.m.

8.3

CVSS4.0

CVE-2025-65106 - LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulneraโ€ฆ

๐Ÿ“… Published: Nov. 21, 2025, 9:43 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 10:16 p.m.

8.7

CVSS4.0

CVE-2025-65102 - PJSIP is vulnerable to buffer overflow in Opus PLC

PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may be less than that. This issue affects PJSIP users who use the Opus audio coโ€ฆ

๐Ÿ“… Published: Nov. 21, 2025, 9:36 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 10:16 p.m.

6.9

CVSS4.0

CVE-2025-65092 - ESP32-P4 JPEG Decoder Header Parsing Vulnerability

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the ESP32-P4 uses its hardware JPEG decoder, the software parser lacks necessary validation checks. A specially crafted (malicious) JPEG image could exploit the parsing routine and triโ€ฆ

๐Ÿ“… Published: Nov. 21, 2025, 9:33 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 10:16 p.m.
Total resulsts: 343921
Page 2406 of 34,393
ยซ previous page ยป next page
Filters