7.1

CVSS4.0

CVE-2025-33039 - Qsync Central

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have…

πŸ“… Published: Oct. 3, 2025, 6:08 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 3:01 p.m.

5.3

CVSS4.0

CVE-2025-33034 - Qsync Central

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.…

πŸ“… Published: Oct. 3, 2025, 6:08 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 3:04 p.m.

5.3

CVSS4.0

CVE-2024-56804 - Video Station

An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Video Station 5.8.4 and later

πŸ“… Published: Oct. 3, 2025, 6:08 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 3:07 p.m.

7.6

CVSS3.1

CVE-2025-52653 - Cross Site Scripting vulnerability in the web application

HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in unauthorized actions or access.

πŸ“… Published: Oct. 3, 2025, 5:59 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 4:50 p.m.

7

CVSS3.1

CVE-2025-46817 - Lua library commands may lead to integer overflow and potential RCE

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exists in all versions of Redis with Lua scripting. Th…

πŸ“… Published: Oct. 3, 2025, 5:52 p.m. πŸ”„ Last Modified: Jan. 27, 2026, 7:37 p.m.

7.1

CVSS3.1

CVE-2025-61593 - Cursor CLI Agent: Sensitive File Overwrite Bypass

Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e. */.cursor/cli.json) allows attackers to modify the content of the files through prompt injection, thus achieving remote code execution. A …

πŸ“… Published: Oct. 3, 2025, 5:28 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 5:30 p.m.

8.8

CVSS3.1

CVE-2025-61592 - Cursor CLI: Arbitrary Code Execution Possible through Permissive CLI Config

Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific CLI configuration from the current working directory (<project>/.cursor/cli.json) could override certain global configurations in Cursor CLI. This allowed users running the CLI in…

πŸ“… Published: Oct. 3, 2025, 5:23 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 5:23 p.m.

8.8

CVSS3.1

CVE-2025-61591 - Cursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code Execution

Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a malicious MCP server and return crafted, maliciously injected commands during the interaction process, leading to command …

πŸ“… Published: Oct. 3, 2025, 4:44 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 5:25 p.m.

7.5

CVSS3.1

CVE-2025-61590 - Cursor is vulnerable to RCE via .code-workspace files using Prompt Injection

Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual Studio Code Workspaces. Workspaces allow users to open more than a single folder and save specific settings (pretty similar to .vscode/settings.json) fo…

πŸ“… Published: Oct. 3, 2025, 4:27 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 5:24 p.m.

7.1

CVSS4.0

CVE-2025-34226 - OpenPLC Runtime v3 Persistent DoS

OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime continues to operate u…

πŸ“… Published: Oct. 3, 2025, 3:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3578 of 34,919
Β« previous page Β» next page
Filters