5.3

CVSS4.0

CVE-2025-22172 -

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:24 p.m.

5.3

CVSS4.0

CVE-2025-22176 -

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:20 p.m.

5.3

CVSS4.0

CVE-2025-22171 -

Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:24 p.m.

5.3

CVSS4.0

CVE-2025-22168 -

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 3:15 p.m.

5.3

CVSS4.0

CVE-2025-22177 -

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:20 p.m.

5.3

CVSS4.0

CVE-2025-22175 -

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.

πŸ“… Published: Oct. 22, 2025, 4:30 p.m. πŸ”„ Last Modified: Oct. 27, 2025, 4:15 p.m.

5.3

CVSS3.1

CVE-2025-62607 - Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

Nautobot Single Source of Truth (SSoT) is an app for Nautobot. Prior to version 3.10.0, an unauthenticated attacker could access this page to view the Service Now public instance name e.g. companyname.service-now.com. This is considered low-value information. This does not expose the Secret, the Se…

πŸ“… Published: Oct. 22, 2025, 3:40 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 9:59 a.m.

2.1

CVSS4.0

CVE-2025-62659 - The CookieConsent extension does not properly use reserved data attributes, thus introducing potent…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki CookieConsent extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki CookieConsent extension: from v0.1.0 before v2.0.0.

πŸ“… Published: Oct. 22, 2025, 3:31 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 9:59 a.m.

6.7

CVSS3.1

CVE-2025-23299 -

NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to execute arbitrary code.

πŸ“… Published: Oct. 22, 2025, 3:14 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 9:59 a.m.

8.8

CVSS3.1

CVE-2025-62606 - my little forum vulnerable to SQL Injection in Bookmark Reordering via bookmarks parameter

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a ful…

πŸ“… Published: Oct. 22, 2025, 3:11 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 9:58 a.m.
Total resulsts: 343919
Page 2786 of 34,392
Β« previous page Β» next page
Filters