4.9

CVSS3.1

CVE-2025-54770 - Grub2: use-after-free in net_set_vlan

A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered when the network module is unloaded from memory. An attacker wโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-54320 -

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 20, 2025, 7:02 p.m.

9.8

CVSS3.1

CVE-2025-63994 -

An arbitrary file upload vulnerability in the /php/UploadHandler.php component of RichFilemanager v2.7.6 allows attackers to execute arbitrary code via uploading a crafted file.

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 31, 2025, 2:04 a.m.

8.4

CVSS3.1

CVE-2025-60455 -

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 8, 2026, 5:02 p.m.

9.8

CVSS3.1

CVE-2025-63217 -

The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 15, 2026, 9:57 p.m.

5.3

CVSS3.1

CVE-2025-63829 -

eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction() function.

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 31, 2025, 2:09 a.m.

6.8

CVSS3.1

CVE-2025-63892 -

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument name/description causes stored cross site scripting.

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 20, 2025, 9:51 p.m.

7.5

CVSS3.1

CVE-2025-56527 -

Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 2, 2025, 7:37 p.m.

5.4

CVSS3.1

CVE-2025-63693 -

The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows low-privilege attackers to construct comment content or request parameters and exโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 20, 2025, 8:07 p.m.

7.3

CVSS3.1

CVE-2025-63602 -

A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0.5, renamed to IntelliBreeze.Maintenance.Service.sys) that lโ€ฆ

๐Ÿ“… Published: Nov. 18, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 31, 2025, 2:24 a.m.
Total resulsts: 349182
Page 2986 of 34,919
ยซ previous page ยป next page
Filters