6.5

CVSS3.1

CVE-2025-0277 - HCL BigFix Mobile is affected by an insecure Content Security Policy (CSP)

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

πŸ“… Published: Oct. 16, 2025, 8:27 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 6:15 p.m.

9.8

CVSS3.1

CVE-2025-54539 - Apache ActiveMQ NMS AMQP Client: Deserialization of Untrusted Data

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers could exploit unbounded deserialization…

πŸ“… Published: Oct. 16, 2025, 8:26 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

6.5

CVSS3.1

CVE-2025-0276 - HCL BigFix Modern Client Management (MCM) is affected by an insecure Content Security Policy (CSP)

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

πŸ“… Published: Oct. 16, 2025, 8:25 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 1:03 p.m.

3.1

CVSS3.1

CVE-2025-10545 - Guest user can add unauthorized team users to private channels

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint

πŸ“… Published: Oct. 16, 2025, 8:24 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 6:02 p.m.

8.1

CVSS3.1

CVE-2025-58075 - Arbitrary Mattermost Team can be joined by manipulating the SAML RelayState

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState

πŸ“… Published: Oct. 16, 2025, 8:20 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

3.1

CVSS3.1

CVE-2025-54499 - Insecure string comparison enables timing attacks

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets

πŸ“… Published: Oct. 16, 2025, 8:17 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 5:58 p.m.

4.3

CVSS3.1

CVE-2025-41443 - Guest user can discover active public channels

Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_id}/channels/ids` endpoint

πŸ“… Published: Oct. 16, 2025, 8:10 a.m. πŸ”„ Last Modified: Oct. 29, 2025, 8:15 a.m.

5.1

CVSS4.0

CVE-2025-41021 - Stored Cross-Site Scripting (XSS) vulnerability in Sergestec's Exito

Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'obs' parameter in '/admin/index.php?action=product_update'. This vulnerability could allow a remote user to send a specially …

πŸ“… Published: Oct. 16, 2025, 8 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 1:11 p.m.

7.1

CVSS4.0

CVE-2025-41020 - Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito

Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'.

πŸ“… Published: Oct. 16, 2025, 7:59 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 1:12 p.m.

9.3

CVSS4.0

CVE-2025-41019 - SQL injection vulnerability in Sergestec's Exito

SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' parameter in '/index.php?view=ticket_detail'.

πŸ“… Published: Oct. 16, 2025, 7:56 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 9:40 a.m.
Total resulsts: 343194
Page 2797 of 34,320
Β« previous page Β» next page
Filters