7.8

CVSS3.1

CVE-2025-11797 - DWG File Parsing Use-After-Free Vulnerability

A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

๐Ÿ“… Published: Nov. 12, 2025, 4:24 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.8

CVSS3.1

CVE-2025-11795 - JPG File Parsing Out-of-Bounds Write Vulnerability

A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

๐Ÿ“… Published: Nov. 12, 2025, 4:24 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

7.6

CVSS3.1

CVE-2025-64293 - WordPress 0 Day Analytics plugin <= 4.0.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Golemiq 0 Day Analytics 0-day-analytics allows SQL Injection.This issue affects 0 Day Analytics: from n/a through <= 4.0.0.

๐Ÿ“… Published: Nov. 12, 2025, 3:52 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:35 p.m.

10

CVSS4.0

CVE-2025-11367 - N-central windows software probe Remote Code Execution

The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization

๐Ÿ“… Published: Nov. 12, 2025, 3:34 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

9.4

CVSS4.0

CVE-2025-11366 - N-central Authentication bypass via path traversal

N-central < 2025.4 is vulnerable to authentication bypass via path traversal

๐Ÿ“… Published: Nov. 12, 2025, 3:33 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 7:32 p.m.

8.4

CVSS4.0

CVE-2025-11700 - N-central Multiple XXE Injection Vulnerabilities

N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure

๐Ÿ“… Published: Nov. 12, 2025, 3:30 p.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 3:15 p.m.

6.9

CVSS4.0

CVE-2025-9316 - N-central unauthenticated sessionID generation

N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.

๐Ÿ“… Published: Nov. 12, 2025, 3:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-13074 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

๐Ÿ“… Published: Nov. 12, 2025, 3:15 p.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 5:26 p.m.

7.3

CVSS4.0

CVE-2025-11567 -

CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is not properly secured.

๐Ÿ“… Published: Nov. 12, 2025, 1:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-11566 -

CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker on the local network to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on the /REST/shutdownnow endpoint.

๐Ÿ“… Published: Nov. 12, 2025, 1:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3036 of 34,919
ยซ previous page ยป next page
Filters