6.1

CVSS4.0

CVE-2025-54811 - OpenPLC_V3

OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value. This leads to a crash when the server loop ends and execution hits an illegal ud2 instruction. This issue can be triggered remotely without authentication by starting the same server multiple ti…

πŸ“… Published: Oct. 1, 2025, 9:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-23297 -

NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged access could modify files in the Frameview SDK directory. A successful exploit of this vulnerability might lead to escalation of privileges.

πŸ“… Published: Oct. 1, 2025, 9:19 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-23355 -

NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and denial of service.

πŸ“… Published: Oct. 1, 2025, 9:19 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

7.5

CVSS3.1

CVE-2025-59538 - Argo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6 and 3.0.17, when the webhook.azuredevops.username and webhook.azuredevops.password are not set in the default configuration, the /api/webhook endpoint…

πŸ“… Published: Oct. 1, 2025, 9:09 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 2:28 p.m.

7.5

CVSS3.1

CVE-2025-59537 - argo-cd is vulnerable to unauthenticated DoS attack via malformed Gogs webhook payload

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients.…

πŸ“… Published: Oct. 1, 2025, 9:01 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 2:34 p.m.

7.5

CVSS3.1

CVE-2025-59531 - Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients.…

πŸ“… Published: Oct. 1, 2025, 8:49 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 2:39 p.m.

5.5

CVSS4.0

CVE-2025-59337 - Discourse: Cross-Site Data Exposure via Backup Restore Metacommand Injection in Multisite Deploymen…

Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. In multisite setups, this allowed an admin of one site to access data or credentials from other sites. This issue is fixed …

πŸ“… Published: Oct. 1, 2025, 8:41 p.m. πŸ”„ Last Modified: Oct. 16, 2025, 5:33 p.m.

7.5

CVSS3.1

CVE-2025-59150 - Suricata: Keyword tls.subjectaltname can lead to NULL-ptr deref

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Version 8.0.0's usage of the tls.subjectaltname keyword can lead to a segmentation fault when the decoded subjectaltname contains a NULL byte. This issue is fixed i…

πŸ“… Published: Oct. 1, 2025, 8:23 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 2:15 p.m.

6.2

CVSS3.1

CVE-2025-59149 - Suricata: Stack buffer overflow in rule parser when processing long keywords with transforms

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In version 8.0.0, rules using keyword ldap.responses.attribute_type (which is long) with transforms can lead to a stack buffer overflow during Suricata startup or d…

πŸ“… Published: Oct. 1, 2025, 8:07 p.m. πŸ”„ Last Modified: Oct. 6, 2025, 5:01 p.m.

3.3

CVSS3.1

CVE-2025-58769 - auth0-PHP: Improper File Type Handling in Bulk User Import

auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications built with the SDK does not validate the file-path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or …

πŸ“… Published: Oct. 1, 2025, 7:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3601 of 34,919
Β« previous page Β» next page
Filters