5.3

CVSS4.0

CVE-2025-0504 - Black Duck SCA Project Privilege Escalation

Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. E…

πŸ“… Published: Nov. 21, 2025, 9:30 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 10:16 p.m.

2.4

CVSS3.1

CVE-2025-31216 -

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.

πŸ“… Published: Nov. 21, 2025, 9:22 p.m. πŸ”„ Last Modified: April 2, 2026, 7:19 p.m.

4.3

CVSS3.1

CVE-2025-31266 -

A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.

πŸ“… Published: Nov. 21, 2025, 9:22 p.m. πŸ”„ Last Modified: April 2, 2026, 7:19 p.m.

4.3

CVSS3.1

CVE-2025-43374 -

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-b…

πŸ“… Published: Nov. 21, 2025, 9:22 p.m. πŸ”„ Last Modified: April 2, 2026, 7:20 p.m.

5.5

CVSS3.1

CVE-2025-31248 -

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access sensitive user data.

πŸ“… Published: Nov. 21, 2025, 9:22 p.m. πŸ”„ Last Modified: April 2, 2026, 7:19 p.m.

8.8

CVSS3.1

CVE-2025-11087 - Zegen Core <= 2.0.1 - Cross-Site Request Forgery to Arbitrary File Upload

The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.0.1. This is due to missing nonce validation and missing file type validation in the '/custom-font-code/custom-fonts-uploads.php' file. This makes it possible…

πŸ“… Published: Nov. 21, 2025, 8:29 p.m. πŸ”„ Last Modified: April 8, 2026, 4:36 p.m.

6.8

CVSS4.0

CVE-2025-13524 -

Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call participant to continue receiving audio input from another user after they close their call window. This issue occurs under certain conditions, which require th…

πŸ“… Published: Nov. 21, 2025, 8:03 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 10:16 p.m.

6.3

CVSS3.1

CVE-2025-36149 - IBM Concert Software clickjacking

IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.

πŸ“… Published: Nov. 21, 2025, 7:38 p.m. πŸ”„ Last Modified: Dec. 2, 2025, 4:22 p.m.

5.5

CVSS3.1

CVE-2025-48502 -

Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.

πŸ“… Published: Nov. 21, 2025, 7:07 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 6:48 p.m.

5.5

CVSS4.0

CVE-2025-62609 - MLX has Wild Pointer Dereference in load_gguf()

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This is…

πŸ“… Published: Nov. 21, 2025, 6:57 p.m. πŸ”„ Last Modified: Dec. 2, 2025, 4:30 p.m.
Total resulsts: 343921
Page 2407 of 34,393
Β« previous page Β» next page
Filters