7.5

CVSS3.1

CVE-2025-9954 - Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105

Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5.

πŸ“… Published: Oct. 29, 2025, 11:12 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 8:06 p.m.

5.9

CVSS3.1

CVE-2025-54549 - Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafte…

Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

πŸ“… Published: Oct. 29, 2025, 10:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-54548 - On affected platforms, restricted users could view sensitive portions of the config database via a …

On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes)

πŸ“… Published: Oct. 29, 2025, 10:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-54547 - On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions …

On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired

πŸ“… Published: Oct. 29, 2025, 10:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-54546 - On affected platforms, restricted users could use SSH port forwarding to access host-internal servi…

On affected platforms, restricted users could use SSH port forwarding to access host-internal services

πŸ“… Published: Oct. 29, 2025, 10:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-54545 - On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and…

On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges.

πŸ“… Published: Oct. 29, 2025, 10:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-14439 - usd: OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability

No description is available for this CVE.

πŸ“… Published: Oct. 29, 2025, 10:13 p.m. πŸ”„ Last Modified: Oct. 29, 2025, 10:13 p.m.

6.3

CVSS3.1

CVE-2025-13327 - Uv: uv: specially crafted zip archives lead to arbitrary code execution due to parsing differentials

A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring user interaction to install an attacker-controlled package.

πŸ“… Published: Oct. 29, 2025, 10:12 p.m. πŸ”„ Last Modified: March 18, 2026, 3:20 a.m.

4.3

CVSS3.1

CVE-2025-58183 - Unbounded allocation when parsing GNU sparse map in archive/tar

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compr…

πŸ“… Published: Oct. 29, 2025, 10:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-61724 - Excessive CPU consumption in Reader.ReadResponse in net/textproto

The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.

πŸ“… Published: Oct. 29, 2025, 10:10 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 3:30 p.m.
Total resulsts: 349182
Page 3219 of 34,919
Β« previous page Β» next page
Filters