9.8

CVSS3.1

CVE-2025-56218 -

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 27, 2025, 2:28 p.m.

9.8

CVSS3.1

CVE-2025-56221 -

A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 27, 2025, 2:16 p.m.

4

CVSS3.1

CVE-2024-31573 - org.xmlunit/xmlunit-core: XMLUnit Insecure Defaults when Processing XSLT Stylesheets

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2025-62650 -

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen.

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2025, 6:39 p.m.

9.1

CVSS3.1

CVE-2025-57567 -

A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code via the admin panel, โ€ฆ

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-56320 -

Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary code. NOTE: the Supplier reports that this is "Present only in an obsolete, unsupported version no longer in circulation."

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2025-62647 -

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to return a signed AWS upload URL, for any store's path.

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2025, 6:39 p.m.

5

CVSS3.1

CVE-2025-62646 -

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2025, 6:36 p.m.

5

CVSS3.1

CVE-2025-62644 -

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 31, 2025, 6:30 p.m.

5.5

CVSS3.1

CVE-2025-60360 -

radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.

๐Ÿ“… Published: Oct. 17, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 23, 2025, 12:34 p.m.
Total resulsts: 349182
Page 3384 of 34,919
ยซ previous page ยป next page
Filters