6.3

CVSS3.1

CVE-2025-43079 - Local Privilege Escalation via qagent_uninstall.sh Qualys Cloud Agents

The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using absolute paths and without sanitizing the $PATH environment. If the uninstall script is executed with elevated privilege…

πŸ“… Published: Nov. 10, 2025, 5:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-46430 -

Dell Display and Peripheral Manager, versions prior to 2.1.2.12, contains an Execution with Unnecessary Privileges vulnerability in the Installer. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

πŸ“… Published: Nov. 10, 2025, 3:59 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

9.1

CVSS3.1

CVE-2025-12480 -

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

πŸ“… Published: Nov. 10, 2025, 2:20 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

4.2

CVSS3.1

CVE-2025-64457 -

In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

πŸ“… Published: Nov. 10, 2025, 1:28 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

8.4

CVSS3.1

CVE-2025-64456 -

In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation

πŸ“… Published: Nov. 10, 2025, 1:28 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

5.4

CVSS3.1

CVE-2025-64690 -

In JetBrains YouTrack before 2025.3.104432 insecure Junie configuration could lead to data exposure and unauthorized changes

πŸ“… Published: Nov. 10, 2025, 1:28 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 4:13 p.m.

9.6

CVSS3.1

CVE-2025-64689 -

In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure of the global Junie token

πŸ“… Published: Nov. 10, 2025, 1:28 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:39 p.m.

7.4

CVSS3.1

CVE-2025-64688 -

In JetBrains YouTrack before 2025.3.104432 missing VCS URL validation allowed delegation to unauthorized repositories from the Junie widget

πŸ“… Published: Nov. 10, 2025, 1:27 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:56 p.m.

5.4

CVSS3.1

CVE-2025-64687 -

In JetBrains YouTrack before 2025.3.104432 improper access control allowed modify MCP tool logic

πŸ“… Published: Nov. 10, 2025, 1:27 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:59 p.m.

3.1

CVSS3.1

CVE-2025-64686 -

In JetBrains YouTrack before 2025.3.104432 missing user principal cleanup led to reuse of incorrect authorization context

πŸ“… Published: Nov. 10, 2025, 1:27 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 4:03 p.m.
Total resulsts: 348096
Page 2982 of 34,810
Β« previous page Β» next page
Filters