4.6

CVSS3.1

CVE-2025-43418 - Physical Access to Locked Device Allows Sensitive Information Disclosure

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.

πŸ“… Published: Nov. 5, 2025, 6:33 p.m. πŸ”„ Last Modified: April 27, 2026, 11 p.m.

8.8

CVSS3.1

CVE-2023-43000 - webkitgtk: Processing maliciously crafted web content may lead to memory corruption

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

πŸ“… Published: Nov. 5, 2025, 6:33 p.m. πŸ”„ Last Modified: March 12, 2026, 1:25 p.m.

4.8

CVSS4.0

CVE-2025-12745 - QuickJS quickjs.c js_array_buffer_slice buffer over-read

A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is restricted to local execution. The exploit has been made available to the public …

πŸ“… Published: Nov. 5, 2025, 6:32 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 9:50 p.m.

8.4

CVSS3.1

CVE-2025-11093 - Arbitrary Code Execution with higher privileged users in Multiple WSO2 Products via Script Mediator…

An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute arbitrary code within the integration runtime environment. By default, access t…

πŸ“… Published: Nov. 5, 2025, 6:31 p.m. πŸ”„ Last Modified: Jan. 9, 2026, 2:33 a.m.

5.4

CVSS3.1

CVE-2025-31954 - HCL iAutomate is susceptible to a sensitive information disclosure

HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.

πŸ“… Published: Nov. 5, 2025, 6:23 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 6:05 p.m.

8.4

CVSS3.1

CVE-2025-10907 - Authenticated Arbitrary File Upload in Multiple WSO2 Products via SOAP Admin Services Leading to Re…

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to a user-controlled location within the deployment…

πŸ“… Published: Nov. 5, 2025, 6:03 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 9:07 p.m.

6.5

CVSS3.1

CVE-2025-10713 - XML External Entity (XXE) Vulnerability in Multiple WSO2 Products Due to Improper XML Parser Config…

An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities. A successful attack could enable a remote, unaut…

πŸ“… Published: Nov. 5, 2025, 5:18 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 9:07 p.m.

7.3

CVSS3.1

CVE-2025-43990 -

Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

πŸ“… Published: Nov. 5, 2025, 5:01 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

6.7

CVSS3.1

CVE-2025-46366 -

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain confidential information.

πŸ“… Published: Nov. 5, 2025, 4:50 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

6.7

CVSS3.1

CVE-2025-46424 -

Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this vulnerability leading to Denial of service.

πŸ“… Published: Nov. 5, 2025, 4:46 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.
Total resulsts: 349182
Page 3139 of 34,919
Β« previous page Β» next page
Filters