4.8

CVSS4.0

CVE-2025-10909 - Mangati NovoSGA SVG File admin cross site scripting

A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting. Remote exploitation of the attack is po…

πŸ“… Published: Sept. 24, 2025, 4:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-10892 -

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Sept. 24, 2025, 4:17 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

8.8

CVSS3.1

CVE-2025-10891 -

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Sept. 24, 2025, 4:17 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

9.1

CVSS3.1

CVE-2025-10890 -

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Sept. 24, 2025, 4:17 p.m. πŸ”„ Last Modified: Sept. 25, 2025, 3:56 p.m.

8.8

CVSS3.1

CVE-2025-10502 -

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

πŸ“… Published: Sept. 24, 2025, 4:17 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

8.8

CVSS3.1

CVE-2025-10500 -

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Sept. 24, 2025, 4:17 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

8.8

CVSS3.1

CVE-2025-10501 - chromium-browser: Use after free in WebRTC

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Sept. 24, 2025, 4:17 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

8.8

CVSS3.1

CVE-2025-10585 -

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Sept. 24, 2025, 4:17 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

6.9

CVSS4.0

CVE-2025-10360 - Insufficiently Protected Credentials in Puppet Enterprise 2025.4 and 2025.5

In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the system if the user has a Puppet Enterprise Advanced license and has enabled the…

πŸ“… Published: Sept. 24, 2025, 3:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-47329 - Release of Invalid Pointer or Reference in Android Core

Memory corruption while handling invalid inputs in application info setup.

πŸ“… Published: Sept. 24, 2025, 3:33 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.
Total resulsts: 349182
Page 3694 of 34,919
Β« previous page Β» next page
Filters