9.3

CVSS4.0

CVE-2025-6893 -

An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in broken access control has been identified in the /api/v1/setting/data endpoint of the affected device. This flaw allows a low-privileged authenticated user to call…

πŸ“… Published: Oct. 17, 2025, 2:17 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-6892 -

An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploite…

πŸ“… Published: Oct. 17, 2025, 2:07 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS3.1

CVE-2025-62642 -

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account.

πŸ“… Published: Oct. 17, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:39 p.m.

6.5

CVSS3.1

CVE-2025-57164 -

Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.

πŸ“… Published: Oct. 17, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 12:33 p.m.

9.9

CVSS3.1

CVE-2025-62645 -

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.

πŸ“… Published: Oct. 17, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:13 p.m.

3.3

CVSS3.1

CVE-2025-60361 -

radare2 v5.9.8 and before contains a memory leak in the function bochs_open.

πŸ“… Published: Oct. 17, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 12:35 p.m.

3.4

CVSS3.1

CVE-2025-62643 -

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.

πŸ“… Published: Oct. 17, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:32 p.m.

6.5

CVSS3.1

CVE-2025-60514 -

Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts.

πŸ“… Published: Oct. 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-60359 -

radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.

πŸ“… Published: Oct. 17, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 12:34 p.m.

6.4

CVSS3.1

CVE-2025-62648 -

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.

πŸ“… Published: Oct. 17, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:39 p.m.
Total resulsts: 349182
Page 3383 of 34,919
Β« previous page Β» next page
Filters