3.4
CVE-2025-13015 - Spoofing issue in Firefox
Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.
8.8
CVE-2025-13014 - Use-after-free in the Audio/Video component
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
6.1
CVE-2025-13013 - Mitigation bypass in the DOM: Core & HTML component
Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
7.5
CVE-2025-13012 - Race condition in the Graphics component
Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.
8.2
CVE-2025-9408 - Userspace privilege escalation vulnerability on Cortex M
System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege escalation for malicious userspace processes.
7.1
CVE-2025-10918 -
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk
2.7
CVE-2025-64773 -
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
8.1
CVE-2025-11959 - Improper Access Control in Premierturk's Excavation Management Information System
Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Premierturk Information Technologies Inc. Excavation Management Information System allows Footprinting, Functionality Misuse.This issue affects Excavation Managemeโฆ
8.9
CVE-2025-11697 - Studio 5000 ยฎ Simulation Interface Local Code Execution
A local code execution security issue exists within Studio 5000ยฎ Simulation Interfaceโข via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.
8.9
CVE-2025-11696 - Studio 5000 ยฎ Simulation Interface SSRF
A local server-side request forgery (SSRF) security issue exists within Studio 5000ยฎ Simulation Interfaceโข via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes.