7.5

CVSS3.1

CVE-2025-61102 - FRRouting: frr: NULL Pointer Dereference in FRRouting

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 5:49 p.m.

7.5

CVSS3.1

CVE-2025-61099 - FRRouting: frr: NULL Pointer Dereference in FRRouting

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 6:05 p.m.

5.4

CVSS3.1

CVE-2025-60983 -

Reflected Cross Site Scripting vulnerability in Rubikon Banking Solution 4.0.3 in the "Search For Customers Information" endpoints.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2023-37749 -

Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-54968 -

An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remote users to submit jobs, or local users to submit jobs that will execute with the permissions of other users.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 8:31 p.m.

7.2

CVSS3.1

CVE-2025-61482 -

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabl…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-60291 -

An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection configurations.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-27222 -

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to read any local server file th…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 4:57 p.m.

3.7

CVSS3.1

CVE-2025-10939 - Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console

A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /real…

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-61247 -

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php.

πŸ“… Published: Oct. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3281 of 34,919
Β« previous page Β» next page
Filters