8.5

CVSS4.0

CVE-2025-9036 - Rockwell Automation FactoryTalk® Action Manager v1.0.0 Runtime Vulnerability

A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the connection.

📅 Published: Aug. 14, 2025, 1:39 p.m. 🔄 Last Modified: Aug. 14, 2025, 1:39 p.m.

9.3

CVSS4.0

CVE-2025-7353 - Rockwell Automation ControlLogix® Ethernet Remote Code Execution Vulnerability

A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Modules. If a specific IP address is used to connect to the WDB agent, it can allow remote attackers to perform memory dumps, modify memory, and control execution flow.

📅 Published: Aug. 14, 2025, 1:23 p.m. 🔄 Last Modified: Aug. 14, 2025, 1:23 p.m.

5.3

CVSS4.0

CVE-2025-55675 - Apache Superset: Incorrect datasource authorization on REST API

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL, an attacker can enu…

📅 Published: Aug. 14, 2025, 1:18 p.m. 🔄 Last Modified: Aug. 14, 2025, 1:18 p.m.

5.3

CVSS4.0

CVE-2025-55674 - Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended to be disabled, leadi…

📅 Published: Aug. 14, 2025, 1:18 p.m. 🔄 Last Modified: Aug. 14, 2025, 1:18 p.m.

5.3

CVSS4.0

CVE-2025-55672 - Apache Superset: Stored XSS on charts metadata

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they ho…

📅 Published: Aug. 14, 2025, 1:17 p.m. 🔄 Last Modified: Aug. 14, 2025, 1:17 p.m.

5.3

CVSS4.0

CVE-2025-55673 - Apache Superset: Metadata exposure in embedded charts

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user. This…

📅 Published: Aug. 14, 2025, 1:16 p.m. 🔄 Last Modified: Aug. 14, 2025, 1:16 p.m.

5.3

CVSS4.0

CVE-2025-8963 - jeecgboot JimuReport Data Large Screen Template testConnection deserialization

A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. Th…

📅 Published: Aug. 14, 2025, 1:02 p.m. 🔄 Last Modified: Aug. 14, 2025, 1:02 p.m.

8.8

CVSS3.1

CVE-2025-8715 - PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore tar…

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks…

📅 Published: Aug. 14, 2025, 1 p.m. 🔄 Last Modified: Aug. 14, 2025, 1 p.m.

8.8

CVSS3.1

CVE-2025-8714 - PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affec…

📅 Published: Aug. 14, 2025, 1 p.m. 🔄 Last Modified: Aug. 14, 2025, 1 p.m.

3.1

CVSS3.1

CVE-2025-8713 - PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this…

📅 Published: Aug. 14, 2025, 1 p.m. 🔄 Last Modified: Aug. 14, 2025, 1 p.m.
Total resulsts: 305855
Page 32 of 30,586
« previous page » next page
Filters