7.2

CVSS3.1

CVE-2025-54658 -

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1 through 11.1.2 and 11.0.1 and 10.5.1 an…

πŸ“… Published: Oct. 16, 2025, 1:55 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 9:17 a.m.

9.8

CVSS3.1

CVE-2025-9152 - Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, poten…

πŸ“… Published: Oct. 16, 2025, 12:37 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 6:33 p.m.

8.9

CVSS3.1

CVE-2025-9804 - Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST …

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level informa…

πŸ“… Published: Oct. 16, 2025, 12:33 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:40 p.m.

5.7

CVSS3.1

CVE-2025-9955 - Improper Access Control in WSO2 Enterprise Integrator Product via SOAP Admin Services for Logs and …

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs and user-store configuration. A low-privileged user can access log data and user-store configuration details that …

πŸ“… Published: Oct. 16, 2025, 12:14 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 6:32 p.m.

9.8

CVSS3.1

CVE-2025-10611 - Potential Broken Access Control in Multiple WSO2 Products via System REST APIs

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation. Successful exploitation of this vulnerability could lead to a malicious actor gainin…

πŸ“… Published: Oct. 16, 2025, 12:09 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:38 p.m.

0.0

CVE-2025-11854 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22381. Reason: This candidate is a reservation duplicate of CVE-2025-22381. Notes: All CVE users should reference CVE-2025-22381 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

πŸ“… Published: Oct. 16, 2025, 11:49 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 4:43 p.m.

6.3

CVSS4.0

CVE-2025-3930 - Lack of JWT Expiration after Log Out in Strapi

Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be changed). The existe…

πŸ“… Published: Oct. 16, 2025, 10:43 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-58426 -

desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious AppSuite applications.

πŸ“… Published: Oct. 16, 2025, 10:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-58079 -

Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.

πŸ“… Published: Oct. 16, 2025, 10:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-55072 -

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.

πŸ“… Published: Oct. 16, 2025, 10:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3392 of 34,919
Β« previous page Β» next page
Filters