8.1

CVSS3.1

CVE-2025-62610 - Hono Improperly Authorizes JWT Audience Validation

Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an API may accept a valid …

πŸ“… Published: Oct. 22, 2025, 7:24 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 3:56 p.m.

5.7

CVSS4.0

CVE-2025-62513 - OpenBao leaks HTTPRawBody in Audit Logs

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using the ACME functionality of PKI, resulting in short…

πŸ“… Published: Oct. 22, 2025, 7:18 p.m. πŸ”„ Last Modified: Oct. 27, 2025, 8:31 p.m.

4.8

CVSS4.0

CVE-2025-62248 -

A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through …

πŸ“… Published: Oct. 22, 2025, 7:07 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 6:13 p.m.

5.4

CVSS3.1

CVE-2025-24934 - SO_REUSEPORT_LB breaks connect(2) for UDP sockets

Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. However, due to its membership in a load-balancing group, that socket will receive packets originating from any host. This breaks the contract of the connect(2) and implied conne…

πŸ“… Published: Oct. 22, 2025, 5:43 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 9:58 a.m.

9

CVSS4.0

CVE-2025-11957 -

Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.

πŸ“… Published: Oct. 22, 2025, 5:09 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 6:15 p.m.

5.1

CVSS4.0

CVE-2025-11958 -

An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier allows an authenticated user to cause a denial of service to the Security Dashboard via a craftedΒ request.

πŸ“… Published: Oct. 22, 2025, 5:08 p.m. πŸ”„ Last Modified: Nov. 27, 2025, 3:41 p.m.

5.3

CVSS4.0

CVE-2025-22178 -

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:20 p.m.

5.3

CVSS4.0

CVE-2025-22169 -

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:24 p.m.

5.3

CVSS4.0

CVE-2025-22173 -

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:23 p.m.

5.3

CVSS4.0

CVE-2025-22170 -

Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:24 p.m.
Total resulsts: 343920
Page 2785 of 34,392
Β« previous page Β» next page
Filters