7.1

CVSS3.1

CVE-2025-37147 - Secure Boot Bypass allows for Compromise of Hardware Root of Trust

A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or custom firmware on …

πŸ“… Published: Oct. 14, 2025, 4:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-37146 - Unauthorized Filesystem Operations in System Firmware allow Authenticated Remote Code Execution

A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

πŸ“… Published: Oct. 14, 2025, 4:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2025-36730 - Windsurf Prompt Injection via Filename

A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.

πŸ“… Published: Oct. 14, 2025, 4:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS3.1

CVE-2025-37149 -

A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.

πŸ“… Published: Oct. 14, 2025, 3:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2025-11577 - Clevo UEFI firmware exposed Boot Guard private keys, enabling potential abuse of the Boot Guard tru…

Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the …

πŸ“… Published: Oct. 14, 2025, 3:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-8429 - A user with elevated privileges can inject XSS in the ACL Action access configuration page

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Action access configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13…

πŸ“… Published: Oct. 14, 2025, 3:29 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 2:02 p.m.

6.8

CVSS3.1

CVE-2025-54893 - A user with elevated privileges can inject XSS in the Hosts templates configuration page

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts templates configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, …

πŸ“… Published: Oct. 14, 2025, 3:24 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 2:09 p.m.

2.6

CVSS3.1

CVE-2025-31514 -

An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing log…

πŸ“… Published: Oct. 14, 2025, 3:23 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 9:17 a.m.

6.8

CVSS3.1

CVE-2025-46774 -

An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.

πŸ“… Published: Oct. 14, 2025, 3:23 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

4.2

CVSS3.1

CVE-2025-54822 -

An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiProxy 2.0 all versions allows an authent…

πŸ“… Published: Oct. 14, 2025, 3:23 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 10:16 a.m.
Total resulsts: 349182
Page 3440 of 34,919
Β« previous page Β» next page
Filters