8.8

CVSS3.1

CVE-2025-20341 - Cisco Catalyst Center Privilege Escalation Vulnerability

A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by subm…

πŸ“… Published: Nov. 13, 2025, 4:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-64525 - Astro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, …

Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, without sanitization, to build the URL. This has several consequences, the most important of which are: mid…

πŸ“… Published: Nov. 13, 2025, 3:58 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 3:14 p.m.

6.3

CVSS3.1

CVE-2025-64703 - MaxKB has Information Leak in sandbox

MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations by Python code in tool module, although the process run in sandbox. Version 2.3.1 fixes the issue.

πŸ“… Published: Nov. 13, 2025, 3:52 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 2:55 p.m.

7.4

CVSS3.1

CVE-2025-64511 - MaxKB has SSRF in sandbox

MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool module, although the process runs in a sandbox. Version 2.3.1 fixes the issue.

πŸ“… Published: Nov. 13, 2025, 3:51 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 3:13 p.m.

5.3

CVSS3.1

CVE-2025-64718 - js-yaml has prototype pollution in merge (<<)

js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patch…

πŸ“… Published: Nov. 13, 2025, 3:32 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 12:54 p.m.

4.8

CVSS4.0

CVE-2025-13120 - mruby array.c sort_cmp use after free

A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is eb…

πŸ“… Published: Nov. 13, 2025, 3:32 p.m. πŸ”„ Last Modified: March 4, 2026, 3:06 p.m.

7.4

CVSS4.0

CVE-2025-64717 - ZITADEL vulnerable to Account Takeover with deactivated Instance IdP

ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation process allowed auto-linking users from external identity providers to existing users in ZITADEL even if the corresponding IdP …

πŸ“… Published: Nov. 13, 2025, 3:30 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 2:39 p.m.

5.8

CVSS3.1

CVE-2025-64714 - PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated Local File Inclusion exists in the template-switching feature. If `templateselection` is enabled in the configuration, the server trusts the …

πŸ“… Published: Nov. 13, 2025, 3:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-62484 - Zoom Workplace Clients - Inefficient Regular Expression Complexity

Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.

πŸ“… Published: Nov. 13, 2025, 3:07 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

5.3

CVSS3.1

CVE-2025-62483 - Zoom Clients - Improper Removal of Sensitive Information

Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.

πŸ“… Published: Nov. 13, 2025, 3:03 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 8:50 p.m.
Total resulsts: 349182
Page 3020 of 34,919
Β« previous page Β» next page
Filters