5.5

CVSS3.1

CVE-2025-39893 - spi: spi-qpic-snand: unregister ECC engine on probe error and device remove

In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: unregister ECC engine on probe error and device remove The on-host hardware ECC engine remains registered both when the spi_register_controller() function returns with an error and also on device removal. Ch…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

8.7

CVSS4.0

CVE-2025-24525 - Keysight Ixia Vision Product Family Use of Hard-coded Cryptographic Key

Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device. Remediation is availabl…

πŸ“… Published: Sept. 30, 2025, 11:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-55191 - Repository Credentials Race Condition Crashes Argo CD Server

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain a race condition in the repository credentials handler that can cause the Argo CD server to panic and crash when con…

πŸ“… Published: Sept. 30, 2025, 10:52 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 1:11 p.m.

4.8

CVSS4.0

CVE-2025-43826 -

Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allow remote at…

πŸ“… Published: Sept. 30, 2025, 10:36 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:21 p.m.

9.3

CVSS4.0

CVE-2025-10659 - MegaSys Enterprises Telenium Online Web Application OS Command Injection

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs due to the insecure termination of a regular expression check within the endpoint. Because the input is not corr…

πŸ“… Published: Sept. 30, 2025, 8 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-36262 - IBM Planning Analytics Local information disclosure

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.

πŸ“… Published: Sept. 30, 2025, 7:42 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 5:52 p.m.

5.4

CVSS3.1

CVE-2025-36132 - IBM Planning Analytics Local cross-site scripting

IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure …

πŸ“… Published: Sept. 30, 2025, 7:41 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 5:52 p.m.

5.3

CVSS4.0

CVE-2025-43827 -

Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported…

πŸ“… Published: Sept. 30, 2025, 6:57 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:20 p.m.

3.3

CVSS3.1

CVE-2025-11195 - Rapid7 AppSpider Project Name Validation Bypass

Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file to a name that already exists. This issue stems from a lack of effective verification of the uniqueness of project name…

πŸ“… Published: Sept. 30, 2025, 6:12 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 2:15 p.m.

8.7

CVSS3.1

CVE-2025-23293 -

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to information disclosure.

πŸ“… Published: Sept. 30, 2025, 5:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3626 of 34,919
Β« previous page Β» next page
Filters