7.5

CVSS3.1

CVE-2025-64530 - @apollo/composition has Improper Enforcement of Access Control on Interface Types and Fields

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1 allowed some queries to Apollo Router to improperly bypass access controls on types/fields. Apo…

πŸ“… Published: Nov. 13, 2025, 11:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-13131 - Sonarr Service Sonarr.Console.exe default permission

A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Performing manipulation results in incorrect default permissions. The attack is only possible with local access. The vendor…

πŸ“… Published: Nov. 13, 2025, 10:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-13130 - Radarr Service Radarr.Console.exe default permission

A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\ProgramData\Radarr\bin\Radarr.Console.exe of the component Service. Such manipulation leads to incorrect default permissions. The attack can only be performed from a local environment. …

πŸ“… Published: Nov. 13, 2025, 10:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-36236 - AIX Path Traversal

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.

πŸ“… Published: Nov. 13, 2025, 10:01 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 10:11 p.m.

10

CVSS3.1

CVE-2025-36250 - AIX Code Execution

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls. Β This addresses additional attack vectors for a vulnerability that was previously addressed in CVE…

πŸ“… Published: Nov. 13, 2025, 10:01 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:56 p.m.

9

CVSS3.1

CVE-2025-36096 - AIX Insufficiently Protected Credentials

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.

πŸ“… Published: Nov. 13, 2025, 10:01 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:56 p.m.

9.6

CVSS3.1

CVE-2025-36251 - AIX Command Execution

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.

πŸ“… Published: Nov. 13, 2025, 10:01 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:56 p.m.

2.7

CVSS4.0

CVE-2025-64754 - Jitsi Meet has DOM Redirect on Microsoft OAuth Flow

Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This is fixed in version 2.0.10532. No known workarounds are available.

πŸ“… Published: Nov. 13, 2025, 9:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-64753 - grist-core has insufficient access control in endpoints for comparisons between documents and versi…

grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing hashes for versions of that document and receive a full list of changes between versions, even if those changes contained cells, columns, or ta…

πŸ“… Published: Nov. 13, 2025, 9:46 p.m. πŸ”„ Last Modified: Nov. 20, 2025, 9:11 p.m.

6.8

CVSS3.1

CVE-2025-64752 - grist-core has path to server-side requests via websocket

grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature for fetching from a URL that is executed on the server. The privileged network access of server-side requests could offer opportunities for attack escalat…

πŸ“… Published: Nov. 13, 2025, 9:43 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 4:19 p.m.
Total resulsts: 349182
Page 3016 of 34,919
Β« previous page Β» next page
Filters