5.5

CVSS3.1

CVE-2025-23300 - nvidia-display-driver: NVIDIA Display Driver Null pointer dereference

NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific memory resource. A successful exploit of this vulnerability might lead to denial of service.

📅 Published: Oct. 23, 2025, 6:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-54808 - Oxford Nanopore Technologies MinKNOW Insufficiently Protected Credentials

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access the token. If the t…

📅 Published: Oct. 23, 2025, 6:21 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-34156 - Tibbo AggreGate Network Manager < 6.40.05 System Information Exposure

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could ai…

📅 Published: Oct. 23, 2025, 4:30 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-34155 - Tibbo AggreGate Network Manager < 6.40.05 Login Functionality User Enumeration

Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facil…

📅 Published: Oct. 23, 2025, 4:30 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS4.0

CVE-2025-62713 - Kottster app reinitialization can be re-triggered allowing command injection in development mode

Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running in development mode. This affects development mode only, production deployments were never affected. This issue has been …

📅 Published: Oct. 23, 2025, 4:15 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-62169 - OctoPrint-SpoolManager Plugin APIs do not enforce authentication

OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and older of the stable branch, the APIs of the OctoPrint-SpoolManager plugin do not correctly enforce authentication or authorization checks. …

📅 Published: Oct. 23, 2025, 4:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2025-12114 - Serial Console Enabled

Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

📅 Published: Oct. 23, 2025, 3:29 p.m. 🔄 Last Modified: Nov. 10, 2025, 3:08 p.m.

8.1

CVSS3.1

CVE-2025-59048 - OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method

OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation in the AWS auth method. The vulnerability allows an IAM role from an untrusted AWS account to authenticate by impersonating a rol…

📅 Published: Oct. 23, 2025, 3:09 p.m. 🔄 Last Modified: Dec. 5, 2025, 12:33 a.m.

0

CVSS4.0

CVE-2025-1680 -

An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected devic…

📅 Published: Oct. 23, 2025, 1:56 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-1679 -

Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s web interface. This vulnerability is classi…

📅 Published: Oct. 23, 2025, 1:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3300 of 34,919
« previous page » next page
Filters