4.3

CVSS3.1

CVE-2025-27368 - IBM OpenPages Information Disclosure

IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used by the user interface of OpenPages. An authenticated user is able to obtain certain information about system metadata for areas beyond wโ€ฆ

๐Ÿ“… Published: Nov. 12, 2025, 7:11 p.m. ๐Ÿ”„ Last Modified: Nov. 18, 2025, 7:12 p.m.

8.1

CVSS4.0

CVE-2025-64099 - OpenAM allows use of arbitrary OIDC requested claims values in id_token and user_info

Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_supported" parameter is activated, it is possible, thanks to the "oidc-claims-extension.groovy" script, to inject the value of one's choice into a claim contained in the id_token โ€ฆ

๐Ÿ“… Published: Nov. 12, 2025, 6:57 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-61667 - Datadog Linux Host Agent affected by local privilege escalation due to insufficient pycache permissโ€ฆ

The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog Linux Host Agent versions 7.65.0 through 7.70.2 exists due to insufficient permissions being set on the `opt/datadog-agent/python-scripts/__pycache__` directory during installationโ€ฆ

๐Ÿ“… Published: Nov. 12, 2025, 6:50 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-57812 - [BIGSLEEP-434612419] CUPS-Filters has heap-buffer-overflow write in `cfImageLut()`

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. In CUPS-Filters versions up to and including 1.28.1โ€ฆ

๐Ÿ“… Published: Nov. 12, 2025, 6:46 p.m. ๐Ÿ”„ Last Modified: Jan. 20, 2026, 6:11 p.m.

5.3

CVSS4.0

CVE-2025-13057 - Campcodes School Fees Payment Management System ajax.php sql injection

A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_student. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and mโ€ฆ

๐Ÿ“… Published: Nov. 12, 2025, 6:32 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:26 a.m.

5.3

CVSS3.1

CVE-2024-45301 - ZDI-CAN-24744: Mintty Path Conversion Improper Input Validation Information Disclosure Vulnerability

Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to access a file in a specific path. It is triggered by simply printing them out on bash. An attacker can specify an arbitrary network path, negotiate an nโ€ฆ

๐Ÿ“… Published: Nov. 12, 2025, 6:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-25236 -

Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks.

๐Ÿ“… Published: Nov. 12, 2025, 5:41 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-20379 - Risky command safeguards bypass using the โ€œ/services/streams/searchโ€œ REST endpoint through โ€œqโ€œ paraโ€ฆ

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the โ€œadminโ€œ or โ€œpowerโ€œ Splunk roles could run a saved search with a risky command using the โ€ฆ

๐Ÿ“… Published: Nov. 12, 2025, 5:23 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 9:41 p.m.

3.1

CVSS3.1

CVE-2025-20378 - Open Redirect on Web Login endpoint in Splunk Enterprise

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.121, an unauthenticated attacker could craft a malicious URL using the `return_to` parameter of the Splunk Web login endpoint. When an authenticated userโ€ฆ

๐Ÿ“… Published: Nov. 12, 2025, 5:22 p.m. ๐Ÿ”„ Last Modified: Dec. 3, 2025, 9:43 p.m.

8.8

CVSS3.1

CVE-2025-13042 - chromium-browser: Inappropriate implementation in V8

Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Nov. 12, 2025, 4:48 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.
Total resulsts: 349182
Page 3035 of 34,919
ยซ previous page ยป next page
Filters