1

CVSS4.0

CVE-2025-12888 - Constant Time Issue with Xtensa-based ESP32 and X22519

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X2551…

πŸ“… Published: Nov. 21, 2025, 10:50 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 10:50 p.m.

6.3

CVSS4.0

CVE-2025-11936 - Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to ex…

πŸ“… Published: Nov. 21, 2025, 10:24 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 10:24 p.m.

2.3

CVSS4.0

CVE-2025-11933 - DoS Vulnerability in wolfSSL TLS 1.3 CKS Extension

Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions.

πŸ“… Published: Nov. 21, 2025, 10:19 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 10:19 p.m.

8.7

CVSS4.0

CVE-2025-65947 - thread-amount is Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOS

thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resource leaks when querying thread counts on Windows and Apple platforms. In Windows platforms, the thread_amount function calls CreateToolhelp32Snapshot but fails to close the returne…

πŸ“… Published: Nov. 21, 2025, 10:15 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 10:15 p.m.

2.1

CVSS4.0

CVE-2025-11934 - Improper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerify

Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm used. For example when a client sends ECDSA P521 as the supported signature algorithm the server previously co…

πŸ“… Published: Nov. 21, 2025, 10:12 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 10:12 p.m.

8.1

CVSS3.1

CVE-2025-65946 - Roo Code is Vulnerable to Potential Remote Code Execution via zsh Command Validation Bug

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue has been patched in version 3.26.7.

πŸ“… Published: Nov. 21, 2025, 10:11 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 10:11 p.m.

6.3

CVSS4.0

CVE-2025-11935 - Forward Secrecy Violation in WolfSSL TLS 1.3

With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would continue on with the connection using PSK without PFS. This happened when aΒ server responded to a ClientHello containing psk_dhe_ke without a key_share exte…

πŸ“… Published: Nov. 21, 2025, 10:04 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 10:04 p.m.

2.9

CVSS4.0

CVE-2025-65111 - SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incompl…

SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one s…

πŸ“… Published: Nov. 21, 2025, 10:02 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 10:02 p.m.

8.5

CVSS4.0

CVE-2025-65109 - Minder does not sandbox http.send in Rego programs

Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access…

πŸ“… Published: Nov. 21, 2025, 9:56 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:56 p.m.

10

CVSS3.1

CVE-2025-65108 - md-to-pdf is vulnerable to arbitrary JavaScript code execution when parsing front matter

md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of …

πŸ“… Published: Nov. 21, 2025, 9:52 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:52 p.m.
Total resulsts: 319145
Page 3 of 31,915
Β« previous page Β» next page
Filters