7.8

CVSS3.1

CVE-2025-58325 -

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.

πŸ“… Published: Oct. 14, 2025, 3:22 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

6.1

CVSS3.1

CVE-2025-58324 -

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker …

πŸ“… Published: Oct. 14, 2025, 3:22 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

2.5

CVSS3.1

CVE-2025-58903 -

An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.

πŸ“… Published: Oct. 14, 2025, 3:22 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 9:17 a.m.

6.6

CVSS3.1

CVE-2024-48891 -

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via …

πŸ“… Published: Oct. 14, 2025, 3:22 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

8.5

CVSS4.0

CVE-2025-62172 - Home Assistant vulnerable to Stored XSS in Energy dashboard from Energy Entity Name

Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy entity's name field,…

πŸ“… Published: Oct. 14, 2025, 3:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-54891 - A user with elevated privileges can inject XSS in the ACL Resource Access configuration page

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Resource access configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.1…

πŸ“… Published: Oct. 14, 2025, 3:07 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:40 p.m.

8.5

CVSS4.0

CVE-2025-62157 - Argo Workflows exposes artifact repository credentials in workflow-controller logs

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions…

πŸ“… Published: Oct. 14, 2025, 3:06 p.m. πŸ”„ Last Modified: Feb. 6, 2026, 8:49 p.m.

6.8

CVSS3.1

CVE-2025-54892 - A user with elevated privileges can inject XSS in the SNMP traps group configuration page

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, …

πŸ“… Published: Oct. 14, 2025, 2:59 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 2:08 p.m.

6.8

CVSS3.1

CVE-2025-54889 - A user with elevated privileges can inject XSS in the SNMP traps manufacturer configuration page

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps manufacturer configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10…

πŸ“… Published: Oct. 14, 2025, 2:54 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:42 p.m.

8.1

CVSS3.1

CVE-2025-62156 - argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration over…

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 contain a Zip Slip path traversal vulnerability in artifact extraction. During artifact extraction the unpack/untar logic (workf…

πŸ“… Published: Oct. 14, 2025, 2:52 p.m. πŸ”„ Last Modified: Feb. 6, 2026, 8:49 p.m.
Total resulsts: 349182
Page 3443 of 34,919
Β« previous page Β» next page
Filters