7.8

CVSS3.1

CVE-2025-43281 -

The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.

πŸ“… Published: Oct. 15, 2025, 8 p.m. πŸ”„ Last Modified: April 2, 2026, 6:09 p.m.

8.8

CVSS3.1

CVE-2025-11619 -

Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackersΒ in MitM position to intercept traffic.

πŸ“… Published: Oct. 15, 2025, 7:45 p.m. πŸ”„ Last Modified: Dec. 3, 2025, 2:51 p.m.

6.9

CVSS4.0

CVE-2025-62375 - go-witness Improper Verification of AWS EC2 Identity Documents

go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness versions 0.9.2 and earlier the AWS attestor improperly verifies AWS EC2 instance identity documents. Verification can incorrectly succeed when a signature is not present or is emp…

πŸ“… Published: Oct. 15, 2025, 7:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-11832 - APIs Lack Rate Limiting

Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Flooding.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

πŸ“… Published: Oct. 15, 2025, 7:10 p.m. πŸ”„ Last Modified: Nov. 7, 2025, 5:49 p.m.

7.4

CVSS3.1

CVE-2025-62371 - OpenSearch Data Prepper plugins trusts all SSL certificates by default

OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided. Prior to this fix, the OpenSearch sink and source plugins …

πŸ“… Published: Oct. 15, 2025, 5:25 p.m. πŸ”„ Last Modified: Dec. 4, 2025, 6:06 p.m.

9.4

CVSS4.0

CVE-2025-62410 - --disallow-code-generation-from-strings is not sufficient for isolating untrusted JavaScript in hap…

In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating untrusted JavaScript in happy-dom. The untrusted script and the rest of the application still run in the same Isolate/process, so attackers can deploy prototype pollution payloads to…

πŸ“… Published: Oct. 15, 2025, 5:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-62381 - sveltekit-superforms Prototype Pollution in `parseFormData` function of `formData.js`

sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and array properties into Object.prototype, leading to denial o…

πŸ“… Published: Oct. 15, 2025, 5:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.1

CVE-2025-62382 - Frigate Vulnerable to Arbitrary File Read via Export Thumbnail "image_path" parameter

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.2, Frigate's export workflow allows an authenticated operator to nominate any filesystem location as the thumbnail source for a video export. Because that path is copied verbatim into the pu…

πŸ“… Published: Oct. 15, 2025, 5:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-62378 - CommandKit exposes incorrect command name in context object for message command aliases

CommandKit is the discord.js meta-framework for building Discord bots. In versions 1.2.0-rc.1 through 1.2.0-rc.11, a logic flaw exists in the message command handler that affects how the commandName property is exposed to both middleware functions and command execution contexts when handling comman…

πŸ“… Published: Oct. 15, 2025, 5:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-10577 - Sound Research SECOMNService Escalation of Privilege

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities

πŸ“… Published: Oct. 15, 2025, 4:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3399 of 34,919
Β« previous page Β» next page
Filters