6

CVSS3.1

CVE-2025-0033 -

Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.

πŸ“… Published: Oct. 14, 2025, 2:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-59428 - EspoCRM allows arbitrary user creation via stored SVG injection and CSRF

EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, including administrative accounts, through a combination of stored SVG injection and lack of CSRF protection. An attacker with Knowledge Base edit permis…

πŸ“… Published: Oct. 14, 2025, 2:38 p.m. πŸ”„ Last Modified: Oct. 20, 2025, 6:12 p.m.

6.1

CVSS3.1

CVE-2024-44088 - Apache Geode: Reflected XSS

Malicious script injection ('Cross-site Scripting') vulnerability in Apache GeodeΒ web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a specially-crafted link to execute code on the returned page, which could lead to theft of the user's session informati…

πŸ“… Published: Oct. 14, 2025, 2:36 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

7.2

CVSS3.1

CVE-2025-5946 - RCE via the poller reload feature available only to user with high privilege

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection. On the poller parameters page, a user with high privilege is able to concatenate cust…

πŸ“… Published: Oct. 14, 2025, 2:29 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 2:08 p.m.

4.7

CVSS3.1

CVE-2025-10986 -

Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.

πŸ“… Published: Oct. 14, 2025, 2:22 p.m. πŸ”„ Last Modified: Oct. 20, 2025, 3:49 p.m.

6.8

CVSS3.1

CVE-2025-8428 - XSS found in the HTTP loader widget

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (HTTP Loader widget modules) allows Stored XSS.This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before …

πŸ“… Published: Oct. 14, 2025, 2:22 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 2:08 p.m.

7.2

CVSS3.1

CVE-2025-10985 -

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Oct. 14, 2025, 2:20 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

7.2

CVSS3.1

CVE-2025-10243 -

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Oct. 14, 2025, 2:17 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

7.2

CVSS3.1

CVE-2025-10242 -

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Oct. 14, 2025, 2:14 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

5.3

CVSS3.1

CVE-2025-27906 - IBM Content Navigator information disclosure

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.

πŸ“… Published: Oct. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 2:31 p.m.
Total resulsts: 349182
Page 3444 of 34,919
Β« previous page Β» next page
Filters