8.2

CVSS4.0

CVE-2025-66017 - CGGMP21 presignatures can be used in the way that significantly reduces security

CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. In versions 0.6.3 and prior of cggmp21 and version 0.7.0-alpha.1 of cggmp24, presignatures can be used in the way that significantly reduces …

πŸ“… Published: Nov. 25, 2025, 7:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-66016 - CGGMP24 is missing a check in the ZK proof used in CGGMP21

CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. Prior to version 0.6.3, there is a missing check in the ZK proof that enables an attack in which single malicious signer can reconstruct full…

πŸ“… Published: Nov. 25, 2025, 7:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-9624 - OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS

A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.

πŸ“… Published: Nov. 25, 2025, 7:43 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 2:15 p.m.

8.2

CVSS4.0

CVE-2025-65965 - Grype has a credential disclosure vulnerability in Grype JSON output

Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found in Grype, affecting versions 0.68.0 through 0.104.0. If registry credentials are defined and the output of grype is written using the --file or --output json=<file> option, the reg…

πŸ“… Published: Nov. 25, 2025, 7:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-12816 - CVE-2025-12816

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

πŸ“… Published: Nov. 25, 2025, 7:15 p.m. πŸ”„ Last Modified: Jan. 2, 2026, 7:02 p.m.

3.3

CVSS3.1

CVE-2025-65961 - Contao is vulnerable to cross-site scripting in templates

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A worka…

πŸ“… Published: Nov. 25, 2025, 7:06 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 6:20 p.m.

8.7

CVSS4.0

CVE-2025-34350 - UnForm Server < 10.1.15 Doc Flow Unauthenticated File Read

UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Doc Flow feature’s 'arc' endpoint. The Doc Flow module uses the 'arc' handler to retrieve and render pages or resources specified by the user-supplied 'pp' parameter, but it does so…

πŸ“… Published: Nov. 25, 2025, 7:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2025-65960 - Contao is vulnerable to remote code execution in template closures

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, …

πŸ“… Published: Nov. 25, 2025, 6:54 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 5:55 p.m.

7.6

CVSS3.1

CVE-2025-33203 -

NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

πŸ“… Published: Nov. 25, 2025, 6:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-33205 -

NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an untrusted control sphere by use of a predefined variable. A successful exploit of this vulnerability may lead to code execution.

πŸ“… Published: Nov. 25, 2025, 6:07 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.
Total resulsts: 349182
Page 2903 of 34,919
Β« previous page Β» next page
Filters