6.9

CVSS4.0

CVE-2025-41075 - Multiple vulnerabilities in Limesurvey

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optinΒ that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which ca…

πŸ“… Published: Nov. 20, 2025, 12:49 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:59 p.m.

6.9

CVSS4.0

CVE-2025-41074 - Multiple vulnerabilities in Limesurvey

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which …

πŸ“… Published: Nov. 20, 2025, 12:47 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 8 p.m.

7.5

CVSS3.1

CVE-2025-40601 -

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

πŸ“… Published: Nov. 20, 2025, 12:26 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

5.3

CVSS3.1

CVE-2025-40605 -

A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.

πŸ“… Published: Nov. 20, 2025, 12:19 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

6.5

CVSS3.1

CVE-2025-40604 -

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.

πŸ“… Published: Nov. 20, 2025, 12:17 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

9.2

CVSS4.0

CVE-2025-12414 - Looker account compromise via punycode homograph attack

An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted. Self-hosted instances must be upgra…

πŸ“… Published: Nov. 20, 2025, 10:32 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

7.1

CVSS4.0

CVE-2025-11676 - UPnP DOS in TL-WR940N V6

Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated adjacent attackers to perform DoS attack. This issue affects TL-WR940N V6 <= Build 220801.

πŸ“… Published: Nov. 20, 2025, 8:09 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.8

CVSS3.1

CVE-2025-62346 - HCL Glovius Cloud is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious action on a trusted site where the user is authenticated, specifically on one endpoint.

πŸ“… Published: Nov. 20, 2025, 8:08 a.m. πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.

5.1

CVSS4.0

CVE-2025-64984 -

Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.…

πŸ“… Published: Nov. 20, 2025, 6:53 a.m. πŸ”„ Last Modified: Nov. 24, 2025, 9:11 a.m.

6.4

CVSS3.1

CVE-2025-5092 - Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored C…

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

πŸ“… Published: Nov. 20, 2025, 6:38 a.m. πŸ”„ Last Modified: Nov. 24, 2025, 9:10 a.m.
Total resulsts: 319241
Page 34 of 31,925
Β« previous page Β» next page
Filters