7.4

CVSS3.1

CVE-2025-36186 - IBM Db2 privilege escalation

IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations could allow a local user to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.

πŸ“… Published: Nov. 7, 2025, 6:40 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

4.7

CVSS3.1

CVE-2025-64432 - KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer

KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. It was discovered that the virt-api component fails to correctl…

πŸ“… Published: Nov. 7, 2025, 6:38 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 3:56 p.m.

6.3

CVSS3.1

CVE-2025-33012 - IBM Db2 improper account lockout

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.

πŸ“… Published: Nov. 7, 2025, 6:38 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 4:37 p.m.

5.3

CVSS3.1

CVE-2025-2534 - IBM Db2 denial of service

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

πŸ“… Published: Nov. 7, 2025, 6:36 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 4:44 p.m.

5.4

CVSS3.1

CVE-2025-36135 - IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Cross-Site Scripting

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr…

πŸ“… Published: Nov. 7, 2025, 6:26 p.m. πŸ”„ Last Modified: Dec. 11, 2025, 11:44 p.m.

6.5

CVSS3.1

CVE-2024-47118 - IBM Db2 is vulnerable to a denial of service as the server may crash under certain conditions with …

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

πŸ“… Published: Nov. 7, 2025, 6:23 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 4:49 p.m.

8.7

CVSS4.0

CVE-2025-64431 - IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering

Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) attacks through its V2Beta API, allowing authenticated users with specific administrator roles within one organization to access and modify data belongin…

πŸ“… Published: Nov. 7, 2025, 6:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-12829 -

An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to Ion text in such a way that sensitive data in memory could be exposed through UTF-8 escape sequences. To mitigate this issue, users should upgrade to version v1.…

πŸ“… Published: Nov. 7, 2025, 6:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-12873 - Campcodes School File Management update_user.php sql injection

A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to th…

πŸ“… Published: Nov. 7, 2025, 6:02 p.m. πŸ”„ Last Modified: Nov. 18, 2025, 7:39 p.m.

7.8

CVSS3.1

CVE-2025-9458 - PRT File Parsing Memory Corruption Vulnerability

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

πŸ“… Published: Nov. 7, 2025, 6:01 p.m. πŸ”„ Last Modified: May 4, 2026, 2:07 p.m.
Total resulsts: 349182
Page 3105 of 34,919
Β« previous page Β» next page
Filters