1.9

CVSS4.0

CVE-2025-13425 - Denial of Service in OSV-SCALIBR

A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in a panic (index out of range) and an application crash (denial of service) in OSV-SCALIBR.

πŸ“… Published: Nov. 20, 2025, 3:30 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

5.9

CVSS3.1

CVE-2025-36161 - IBM Concert Software Information Disclosure

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

πŸ“… Published: Nov. 20, 2025, 3:26 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

7.2

CVSS3.1

CVE-2025-0645 - Arbitrary File Upload in Narkom Communication Technologies' Pyxis Signage

Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Pyxis Signage: through 31012025.

πŸ“… Published: Nov. 20, 2025, 1:33 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

4.8

CVSS4.0

CVE-2025-13469 - Public Knowledge Project omp/ojs Payment Instructions Setting paymentForm.tpl cross site scripting

A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstruct…

πŸ“… Published: Nov. 20, 2025, 1:32 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

5.3

CVSS4.0

CVE-2025-13468 - SourceCodester Alumni Management System Delete admin_class.php delete_event authorization

A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executing manipulation of the argument ID can lead …

πŸ“… Published: Nov. 20, 2025, 1:32 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 8:01 p.m.

7.2

CVSS3.1

CVE-2025-0643 - XSS in Narkom Communication Technologies' Pyxis Signage

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Stored XSS.This issue affects Pyxis Signage: through 31012025.

πŸ“… Published: Nov. 20, 2025, 1:26 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.9

CVSS4.0

CVE-2025-41076 - Multiple vulnerabilities in Limesurvey

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database eng…

πŸ“… Published: Nov. 20, 2025, 12:52 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:54 p.m.

6.9

CVSS4.0

CVE-2025-41075 - Multiple vulnerabilities in Limesurvey

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optinΒ that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which ca…

πŸ“… Published: Nov. 20, 2025, 12:49 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:59 p.m.

6.9

CVSS4.0

CVE-2025-41074 - Multiple vulnerabilities in Limesurvey

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which …

πŸ“… Published: Nov. 20, 2025, 12:47 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 8 p.m.

7.5

CVSS3.1

CVE-2025-40601 -

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

πŸ“… Published: Nov. 20, 2025, 12:26 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319178
Page 27 of 31,918
Β« previous page Β» next page
Filters