5.8

CVSS4.0

CVE-2025-33044 - exFat Memory Corruption Issue

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local means. Successful exploitation of this vulnerability may lead to memory corruption and impact Integrity and Availability.

πŸ“… Published: Oct. 14, 2025, 2 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 1:45 p.m.

4.6

CVSS4.0

CVE-2025-22833 - FixupArray Pointer Validation in NTFS

APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by local accessing. Successful exploitation of this vulnerability may lead to arbitrary code execution.

πŸ“… Published: Oct. 14, 2025, 2 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 1:44 p.m.

5.8

CVSS4.0

CVE-2025-22832 - Buffer Overflow in NTFS when parsing the ATTRIBUTE_LIST

APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and loss of availability.

πŸ“… Published: Oct. 14, 2025, 2 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 1:42 p.m.

5.8

CVSS4.0

CVE-2025-22831 - Buffer Overflow in NTFS when parsing the VOLUME_NAME

APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and loss of availability.

πŸ“… Published: Oct. 14, 2025, 2 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 1:41 p.m.

7.2

CVSS3.1

CVE-2025-47856 -

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI reques…

πŸ“… Published: Oct. 14, 2025, 1:42 p.m. πŸ”„ Last Modified: Oct. 16, 2025, 1:10 p.m.

7.7

CVSS4.0

CVE-2025-9178 - Rockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service Vulnerability

A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP communication using crafted payloads. The security issue could result in no CIP communication with 1715 EtherNet/IP Adapter.A restart is required to recover.

πŸ“… Published: Oct. 14, 2025, 12:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2025-9177 - Rockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service Vulnerability

A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the web server. This could result in a web server crash however; this does not impact I/O control or communicationΒ . A power cycle is required to recover an…

πŸ“… Published: Oct. 14, 2025, 12:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-7330 - Rockwell Automation 1783-NATR Cross-Site Request Forgery Vulnerability

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.

πŸ“… Published: Oct. 14, 2025, 12:43 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 9:41 p.m.

9.8

CVSS3.1

CVE-2025-10610 - SQLi in SFS Winsure

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure allows Blind SQL Injection.This issue affects Winsure: through Version dated 21.08.2025.

πŸ“… Published: Oct. 14, 2025, 12:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11498 - CSV Formula Injection Vulnerability

An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attack…

πŸ“… Published: Oct. 14, 2025, 12:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3445 of 34,919
Β« previous page Β» next page
Filters