0.0

CVE-2025-61850 -

Not used

๐Ÿ“… Published: Oct. 1, 2025, 6:21 p.m. ๐Ÿ”„ Last Modified: Oct. 2, 2025, 2:55 a.m.

0.0

CVE-2025-61849 -

Not used

๐Ÿ“… Published: Oct. 1, 2025, 6:21 p.m. ๐Ÿ”„ Last Modified: Oct. 2, 2025, 2:55 a.m.

0.0

CVE-2025-61847 -

Not used

๐Ÿ“… Published: Oct. 1, 2025, 6:21 p.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 2:55 a.m.

7.6

CVSS4.0

CVE-2025-8679 - ExtremeGuest Essentials Captive Portal Unauthenticated Brute Force

In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an unauthenticated device to be marked as authenticated and obโ€ฆ

๐Ÿ“… Published: Oct. 1, 2025, 5:19 p.m. ๐Ÿ”„ Last Modified: Jan. 15, 2026, 2:17 a.m.

5.9

CVSS3.1

CVE-2023-49883 - IBM Transformation Extender Advanced information disclosure

IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

๐Ÿ“… Published: Oct. 1, 2025, 5:07 p.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 5:38 p.m.

5.1

CVSS3.1

CVE-2023-50300 - IBM Transformation Extender Advanced improper access control

IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.

๐Ÿ“… Published: Oct. 1, 2025, 5:07 p.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 5:39 p.m.

6.3

CVSS3.1

CVE-2023-49881 - IBM Transformation Extender Advanced session fixation

IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

๐Ÿ“… Published: Oct. 1, 2025, 5:05 p.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 5:38 p.m.

5.1

CVSS4.0

CVE-2025-34182 - Deciso OPNsense < 25.7.4 /interfaces_ppps_edit.php ptpid Stored XSS

In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the parameter ptpid is not sanitized of HTML-related characters/strings. This value is directly displayed when visiting the page/interfaces_assign.php, which can result in stored cross-site โ€ฆ

๐Ÿ“… Published: Oct. 1, 2025, 5:01 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-11233 - Rust standard library didn't detect all path separators on Cygwin

Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cygwin target (`x86_64-pc-cygwin`) didn't correctly handle path separators, causing the standard library's Path API to ignore path components separated by backslashes. Due to this, programs compiled for Cygwin that validate paths could miโ€ฆ

๐Ÿ“… Published: Oct. 1, 2025, 4:49 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-20357 - Cisco CyberVision Center Reports Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-bโ€ฆ

๐Ÿ“… Published: Oct. 1, 2025, 4:12 p.m. ๐Ÿ”„ Last Modified: Oct. 18, 2025, 1:55 a.m.
Total resulsts: 349182
Page 3603 of 34,919
ยซ previous page ยป next page
Filters