5.5

CVSS4.0

CVE-2025-13466 - body-parser vulnerable to denial of service when url encoding is used

body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send payloads containing thousands of parameters within the default 100KB request size limit, causing elevated CPU and memory usage. This can…

πŸ“… Published: Nov. 24, 2025, 6:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-36112 - IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1Β could reveal sensitive server IP configuration information to an unauthorized user.

πŸ“… Published: Nov. 24, 2025, 6:25 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 4:05 p.m.

8.2

CVSS3.1

CVE-2025-13609 - Keylime: keylime: registrar allows identity takeover via duplicate uuid registration

A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This action overwrites the legitimate agent's identity, enabling the at…

πŸ“… Published: Nov. 24, 2025, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS3.1

CVE-2025-10555 - Stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Servic…

A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

πŸ“… Published: Nov. 24, 2025, 3:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS3.1

CVE-2025-10554 - Stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager fr…

A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

πŸ“… Published: Nov. 24, 2025, 3:31 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:50 p.m.

8.3

CVSS3.1

CVE-2025-44018 -

A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

πŸ“… Published: Nov. 24, 2025, 3:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-12978 - CVE-2025-12978

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows crafted inputs where a tag prefix is incorrectly treated as a full match. A remote attacker with authenticated or exposed acc…

πŸ“… Published: Nov. 24, 2025, 2:42 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 3:36 p.m.

6.5

CVSS3.1

CVE-2025-12969 - CVE-2025-12969

Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authenti…

πŸ“… Published: Nov. 24, 2025, 2:41 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 3:36 p.m.

5.3

CVSS3.1

CVE-2025-12972 - CVE-2025-12972

Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Flue…

πŸ“… Published: Nov. 24, 2025, 2:40 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 3:36 p.m.

9.1

CVSS3.1

CVE-2025-12977 - CVE-2025-12977

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid t…

πŸ“… Published: Nov. 24, 2025, 2:40 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 3:36 p.m.
Total resulsts: 349182
Page 2916 of 34,919
Β« previous page Β» next page
Filters