1.8

CVSS3.1

CVE-2025-64345 - Wasmtime provides unsound API access to a WebAssembly shared linear memory

Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API contains an unsound interaction where a WebAssembly shared linear memory could be viewed as a type which provides safe access to the host (Rust) to the contents of the linear mem…

πŸ“… Published: Nov. 12, 2025, 9:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-33119 - IBM QRadar SIEM Information Disclosure

IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user.

πŸ“… Published: Nov. 12, 2025, 9:19 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:27 p.m.

5.4

CVSS3.1

CVE-2025-36223 - IBM OpenPages Host Header Injection

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

πŸ“… Published: Nov. 12, 2025, 9:04 p.m. πŸ”„ Last Modified: Nov. 18, 2025, 7:14 p.m.

6.9

CVSS4.0

CVE-2025-13063 - DinukaNavaratna Dee Store authorization

A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. The attack may be performed from remote. The exploit has been published and may be used. Multiple endpoints are affected.

πŸ“… Published: Nov. 12, 2025, 9:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS3.1

CVE-2025-64186 - Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted Enclaves

Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verification logic in versions of `evervault-go` prior to 1.3.2 that may allow incomplete documents to pass validation. This may cause the client to trust an enclave operator that does n…

πŸ“… Published: Nov. 12, 2025, 8:34 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 4:57 p.m.

5.3

CVSS4.0

CVE-2025-13061 - itsourcecode Online Voting System index.php unrestricted upload

A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Performing manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.

πŸ“… Published: Nov. 12, 2025, 8:32 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:31 p.m.

3.8

CVSS3.1

CVE-2025-64170 - sudo-rs: Partial password reveal is possible after timeout

sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does not press return for an extended period, a password timeout may occur. When this happens, the keystrokes that were entered are…

πŸ“… Published: Nov. 12, 2025, 8:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-46608 -

Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unautho…

πŸ“… Published: Nov. 12, 2025, 8:12 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 8:39 p.m.

6.9

CVSS4.0

CVE-2025-13060 - SourceCodester Survey Application System view_survey.php sql injection

A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown function of the file /view_survey.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and ma…

πŸ“… Published: Nov. 12, 2025, 8:02 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:32 p.m.

5.3

CVSS4.0

CVE-2025-13059 - SourceCodester Alumni Management System manage_career.php sql injection

A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to…

πŸ“… Published: Nov. 12, 2025, 8:02 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 12:33 p.m.
Total resulsts: 349182
Page 3033 of 34,919
Β« previous page Β» next page
Filters