4.8

CVSS4.0

CVE-2025-61931 -

Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attacker to execute an arbitrary script in a logged-in user's web browser.

๐Ÿ“… Published: Oct. 24, 2025, 5:17 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

5.1

CVSS4.0

CVE-2025-58070 -

Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to execute an arbitrary script in a logged-in user's web browser.

๐Ÿ“… Published: Oct. 24, 2025, 5:17 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

5.5

CVSS3.1

CVE-2025-40021 - tracing: dynevent: Add a missing lockdown check on dynevent

In the Linux kernel, the following vulnerability has been resolved: tracing: dynevent: Add a missing lockdown check on dynevent Since dynamic_events interface on tracefs is compatible with kprobe_events and uprobe_events, it should also check the lockdown status and reject if it is set.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:12 p.m.

7.5

CVSS3.1

CVE-2025-60569 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2025, 2:37 a.m.

5.5

CVSS3.1

CVE-2025-40023 - drm/xe/vf: Don't expose sysfs attributes not applicable for VFs

In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Don't expose sysfs attributes not applicable for VFs VFs can't read BMG_PCIE_CAP(0x138340) register nor access PCODE (already guarded by the info.skip_pcode flag) so we shouldn't expose attributes that require any of tโ€ฆ

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

7.5

CVSS3.1

CVE-2025-60551 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the next_page parameter in the function formDeviceReboot.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2025, 2:31 a.m.

7.5

CVSS3.1

CVE-2025-60549 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAutoDetecWAN_wizard4.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2025, 2:32 a.m.

9.8

CVSS3.1

CVE-2025-60548 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLanSetupRouterSettings.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2025, 2:32 a.m.

8.2

CVSS3.1

CVE-2025-46183 -

The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in unintended code execution or other malicious behavior on the target system.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:12 p.m.

7.5

CVSS3.1

CVE-2025-60570 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLogDnsquery.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2025, 2:37 a.m.
Total resulsts: 343947
Page 2770 of 34,395
ยซ previous page ยป next page
Filters