9.3

CVSS4.0

CVE-2025-10678 - Admin with default credentials in NetBird VPN

NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not ch…

📅 Published: Oct. 20, 2025, 3:41 p.m. 🔄 Last Modified: Oct. 21, 2025, 7:31 p.m.

0.0

CVE-2025-40006 - mm/hugetlb: fix folio is still mapped when deleted

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix folio is still mapped when deleted Migration may be raced with fallocating hole. remove_inode_single_folio will unmap the folio if the folio is still mapped. However, it's called without folio lock. If the foli…

📅 Published: Oct. 20, 2025, 3:26 p.m. 🔄 Last Modified: Oct. 21, 2025, 7:31 p.m.

7.2

CVSS3.1

CVE-2025-57738 - Apache Syncope: Remote Code Execution by delegated administrators

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery…

📅 Published: Oct. 20, 2025, 2:43 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

5.5

CVSS3.1

CVE-2025-8884 - IDOR in VHS Electronic Software's ACE Center

Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers.This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255.

📅 Published: Oct. 20, 2025, 2:36 p.m. 🔄 Last Modified: Oct. 21, 2025, 7:31 p.m.

7.8

CVSS3.1

CVE-2025-41390 - TruffleHog: specially crafted git repository can lead to arbitrary code execution

An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code execution. An attacker can provide a malicious respository to trigger this vulnerability.

📅 Published: Oct. 20, 2025, 2:15 p.m. 🔄 Last Modified: Nov. 3, 2025, 6:16 p.m.

5.9

CVSS4.0

CVE-2025-11680 - Out-of-bounds Write in libwebsockets PNG parsing

Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a…

📅 Published: Oct. 20, 2025, 2:04 p.m. 🔄 Last Modified: Oct. 21, 2025, 7:31 p.m.

5.9

CVSS4.0

CVE-2025-11679 - Out-of-bounds Read in libwebsockets PNG parsing

Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contai…

📅 Published: Oct. 20, 2025, 1:58 p.m. 🔄 Last Modified: Oct. 21, 2025, 7:31 p.m.

7.5

CVSS4.0

CVE-2025-11678 - Stack-based Buffer Overflow in libwebsockets DNS response parsing

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label l…

📅 Published: Oct. 20, 2025, 1:51 p.m. 🔄 Last Modified: Oct. 21, 2025, 7:31 p.m.

6.3

CVSS4.0

CVE-2025-11677 - Use After Free in libwebsockets WebSocket server

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.

📅 Published: Oct. 20, 2025, 1:41 p.m. 🔄 Last Modified: Oct. 24, 2025, 10:54 a.m.

5.3

CVSS4.0

CVE-2025-8349 - Cross-Site Scripting (XSS) stored in Tawk Live Chat

Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by uploading a malicious PDF with JavaScript payload through the chatbot. The PDF is stored by the application and subsequently displayed witho…

📅 Published: Oct. 20, 2025, 9:56 a.m. 🔄 Last Modified: March 24, 2026, 3:42 p.m.
Total resulsts: 343923
Page 2841 of 34,393
« previous page » next page
Filters