7.2

CVSS3.1

CVE-2025-0643 - XSS in Narkom Communication Technologies' Pyxis Signage

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Stored XSS.This issue affects Pyxis Signage: through 31012025.

πŸ“… Published: Nov. 20, 2025, 1:26 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.9

CVSS4.0

CVE-2025-41076 - Multiple vulnerabilities in Limesurvey

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database eng…

πŸ“… Published: Nov. 20, 2025, 12:52 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:54 p.m.

6.9

CVSS4.0

CVE-2025-41075 - Multiple vulnerabilities in Limesurvey

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optinΒ that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which ca…

πŸ“… Published: Nov. 20, 2025, 12:49 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:59 p.m.

6.9

CVSS4.0

CVE-2025-41074 - Multiple vulnerabilities in Limesurvey

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which …

πŸ“… Published: Nov. 20, 2025, 12:47 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 8 p.m.

7.5

CVSS3.1

CVE-2025-40601 -

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

πŸ“… Published: Nov. 20, 2025, 12:26 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

5.3

CVSS3.1

CVE-2025-40605 -

A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.

πŸ“… Published: Nov. 20, 2025, 12:19 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.5

CVSS3.1

CVE-2025-40604 -

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.

πŸ“… Published: Nov. 20, 2025, 12:17 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

9.2

CVSS4.0

CVE-2025-12414 - Looker account compromise via punycode homograph attack

An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted. Self-hosted instances must be upgra…

πŸ“… Published: Nov. 20, 2025, 10:32 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

7.1

CVSS4.0

CVE-2025-11676 - UPnP DOS in TL-WR940N V6

Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated adjacent attackers to perform DoS attack. This issue affects TL-WR940N V6 <= Build 220801.

πŸ“… Published: Nov. 20, 2025, 8:09 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.8

CVSS3.1

CVE-2025-62346 - HCL Glovius Cloud is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious action on a trusted site where the user is authenticated, specifically on one endpoint.

πŸ“… Published: Nov. 20, 2025, 8:08 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319173
Page 27 of 31,918
Β« previous page Β» next page
Filters