8.5

CVSS3.1

CVE-2025-33108 - IBM Backup Recovery and Media Services for i code execution

IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to a library unqualified call made by a BRMS program. A malicious actor could cause user-controlled code to run with component access to…

πŸ“… Published: June 14, 2025, 12:25 a.m. πŸ”„ Last Modified: June 14, 2025, 1:15 a.m.

8.1

CVSS3.1

CVE-2025-24919 - Dell ControlVault3/ControlVault3 Plus deserialization of untrusted input vulnerability

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromi…

πŸ“… Published: June 13, 2025, 9:48 p.m. πŸ”„ Last Modified: June 13, 2025, 10:15 p.m.

8.8

CVSS3.1

CVE-2025-25215 - Dell ControlVault3/ControlVault3 Plus cv_close arbitrary free vulnerability

An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerabili…

πŸ“… Published: June 13, 2025, 9:26 p.m. πŸ”„ Last Modified: June 13, 2025, 10:15 p.m.

5.2

CVSS4.0

CVE-2025-6083 - ExtremeCloud Universal ZTNA Improper Authorization

In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the entire table instead of being restricted to their specific owner_id.

πŸ“… Published: June 13, 2025, 9:06 p.m. πŸ”„ Last Modified: June 13, 2025, 10:15 p.m.

8.8

CVSS3.1

CVE-2025-25050 - Dell ControlVault3/ControlVault3 Plus cv_upgrade_sensor_firmware out-of-bounds write vulnerability

An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can issue an API call t…

πŸ“… Published: June 13, 2025, 9:03 p.m. πŸ”„ Last Modified: June 13, 2025, 9:15 p.m.

8.8

CVSS3.1

CVE-2025-24922 - Dell ControlVault3/ControlVault3 Plus securebio_identify stack-based buffer overflow vulnerability

A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior toΒ 6.2.26.36. A specially crafted malicious cv_object can lead to a arbitrary code execution. An attacker can issue an API call t…

πŸ“… Published: June 13, 2025, 8:51 p.m. πŸ”„ Last Modified: June 13, 2025, 9:49 p.m.

8.4

CVSS3.1

CVE-2025-24311 - Dell ControlVault3/ControlVault3 Plus cv_send_blockdata out-of-bounds read vulnerability

An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this…

πŸ“… Published: June 13, 2025, 8:42 p.m. πŸ”„ Last Modified: June 13, 2025, 9:15 p.m.

4.4

CVSS4.0

CVE-2025-49598 - conda-forge-ci-setup Allows Arbitrary Code Execution via Insecure Version Parsing

conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feedstock setup script is vulnerable due to the unsafe use of the eval function when parsing version information from a custom-formatted meta.yaml file. An attacker controlling meta.y…

πŸ“… Published: June 13, 2025, 8:22 p.m. πŸ”„ Last Modified: June 13, 2025, 9:15 p.m.

9.4

CVSS4.0

CVE-2025-49596 - MCP Inspector proxy server lacks authentication between the Inspector client and proxy

The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. User…

πŸ“… Published: June 13, 2025, 8:11 p.m. πŸ”„ Last Modified: June 13, 2025, 8:15 p.m.

3.9

CVSS3.1

CVE-2025-49597 - handcraftedinthealps goodby-csv Potential Gadget Chain allowing Remote Code Execution

handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export library. Prior to 1.4.3, goodby-csv could be used as part of a chain of methods that is exploitable when an insecure deserialization vulnerability exists in an application. This so-ca…

πŸ“… Published: June 13, 2025, 7:51 p.m. πŸ”„ Last Modified: June 13, 2025, 8:15 p.m.
Total resulsts: 297973
Page 3 of 29,798
Β« previous page Β» next page
Filters