4.8

CVSS4.0

CVE-2025-12199 - dnsmasq Config File network.c check_servers null pointer dereference

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and int…

πŸ“… Published: Oct. 27, 2025, 1:02 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:47 p.m.

8.5

CVSS4.0

CVE-2025-12198 - dnsmasq Config File util.c parse_hex heap-based overflow

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and int…

πŸ“… Published: Oct. 27, 2025, 12:58 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:47 p.m.

2.7

CVSS3.1

CVE-2025-6601 - Business Logic Errors in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

πŸ“… Published: Oct. 27, 2025, 12:06 a.m. πŸ”„ Last Modified: Nov. 24, 2025, 7:26 a.m.

7.5

CVSS3.1

CVE-2025-10497 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

πŸ“… Published: Oct. 27, 2025, 12:05 a.m. πŸ”„ Last Modified: Oct. 28, 2025, 3:02 p.m.

6.5

CVSS3.1

CVE-2025-11971 - Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

πŸ“… Published: Oct. 27, 2025, 12:05 a.m. πŸ”„ Last Modified: Oct. 28, 2025, 3 p.m.

6.5

CVSS3.1

CVE-2025-11974 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.

πŸ“… Published: Oct. 27, 2025, 12:05 a.m. πŸ”„ Last Modified: Oct. 28, 2025, 2:59 p.m.

7.5

CVSS3.1

CVE-2025-11447 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.

πŸ“… Published: Oct. 27, 2025, 12:05 a.m. πŸ”„ Last Modified: Oct. 28, 2025, 2:58 p.m.

7.5

CVSS3.1

CVE-2025-27225 -

TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:33 p.m.

6.5

CVSS3.1

CVE-2025-54970 -

An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, this may allow remote or local users to abort jobs or read information without the permissions of the job owner.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:29 p.m.

6.1

CVSS3.1

CVE-2025-54965 -

An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize the job ID parameter before using it in the job status page. An attacker who is able to social engineer a user into clicking a malicious link may be able to execute arbitrary Jav…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 4:58 p.m.
Total resulsts: 345143
Page 2876 of 34,515
Β« previous page Β» next page
Filters