6.4

CVSS3.1

CVE-2025-14525 - kubevirt: kubevirt: VM administration denial of service via guest agent

No description is available for this CVE.

πŸ“… Published: Jan. 9, 2026, 2:02 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 2:02 a.m.

2.3

CVSS4.0

CVE-2026-22712 - ApprovedRevs allows bypassing the inline CSS sanitizer

Improper Encoding or Escaping of OutputΒ due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRevs Extension: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 9, 2026, 12:06 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 8:15 p.m.

2.3

CVSS4.0

CVE-2026-22713 - Stored XSS through edit summaries in GrowthExperiments

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GrowthExperiments Extension: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 8:15 p.m.

5.4

CVSS3.1

CVE-2025-67281 -

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user to access the database and its content.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 5:15 p.m.

6.5

CVSS3.1

CVE-2025-67278 -

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 5:15 p.m.

0.0

CVE-2025-56225 -

fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:24 p.m.

0.0

CVE-2025-70161 -

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbit…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:24 p.m.

6.5

CVSS3.1

CVE-2026-0665 - qemu-kvm: Heap off-by-one in KVM Xen PHYSDEVOP_map_pirq

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, midnight

7.5

CVSS3.1

CVE-2025-67133 -

An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 5:15 p.m.

5.4

CVSS3.1

CVE-2025-67280 -

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users and access sensitive data of another user.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 9, 2026, 5:15 p.m.
Total resulsts: 327160
Page 35 of 32,716
Β« previous page Β» next page
Filters