4.6

CVSS4.0

CVE-2025-62267 -

Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 35 through update 92 allow remote attackers to inject arbitrary we…

πŸ“… Published: Oct. 31, 2025, 6:12 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 5:04 p.m.

5.1

CVSS4.0

CVE-2025-62264 -

Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows remote attackers to inject arbitrary web script or HTML via the…

πŸ“… Published: Oct. 31, 2025, 5:32 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 5:11 p.m.

4.8

CVSS3.1

CVE-2025-59501 - Microsoft Configuration Manager Spoofing Vulnerability

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

πŸ“… Published: Oct. 31, 2025, 4:45 p.m. πŸ”„ Last Modified: Feb. 22, 2026, 5:26 p.m.

1.8

CVSS4.0

CVE-2025-6075 - Quadratic complexity in os.path.expandvars() with user-controlled template

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

πŸ“… Published: Oct. 31, 2025, 4:41 p.m. πŸ”„ Last Modified: March 3, 2026, 2:43 p.m.

6.9

CVSS4.0

CVE-2025-12554 - Missing Security Headers

Missing Security Headers.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 31, 2025, 3:52 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:48 p.m.

8.4

CVSS3.1

CVE-2025-12509 - Scripts for the module Global_Shipping executable on BRAIN2 Server

On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator rights.

πŸ“… Published: Oct. 31, 2025, 3:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2025-12508 - Unencrypted communication to Active Directory services

When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confidentiality.

πŸ“… Published: Oct. 31, 2025, 3:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-12507 - Insecure service configuration – unquoted path

The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.

πŸ“… Published: Oct. 31, 2025, 3:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-12553 - Server Certificate Verification Disabled

Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 31, 2025, 3:48 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:48 p.m.

6.9

CVSS4.0

CVE-2025-12552 - Insufficient Password Policy

Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 31, 2025, 3:43 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:49 p.m.
Total resulsts: 349182
Page 3188 of 34,919
Β« previous page Β» next page
Filters