5.3

CVSS3.1

CVE-2025-48459 - Apache IoTDB: Deserialization of untrusted Data

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue.

๐Ÿ“… Published: Sept. 24, 2025, 7:57 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

7.8

CVSS3.1

CVE-2025-58319 - File Parsing Memory Corruption in CNCSoft-G2

Delta Electronics CNCSoft-G2ย lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

๐Ÿ“… Published: Sept. 24, 2025, 6:42 a.m. ๐Ÿ”„ Last Modified: Sept. 25, 2025, 6:19 p.m.

7.8

CVSS3.1

CVE-2025-58317 - File Parsing Memory Corruption in CNCSoft-G2

Delta Electronics CNCSoft-G2ย lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

๐Ÿ“… Published: Sept. 24, 2025, 6:38 a.m. ๐Ÿ”„ Last Modified: March 18, 2026, 5:26 a.m.

0.0

CVE-2025-10904 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: Sept. 24, 2025, 6:04 a.m. ๐Ÿ”„ Last Modified: Oct. 7, 2025, 11:15 p.m.

5.3

CVSS4.0

CVE-2025-43819 -

A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old useโ€ฆ

๐Ÿ“… Published: Sept. 24, 2025, 1:37 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 6:20 p.m.

6.9

CVSS4.0

CVE-2025-43779 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code via _com_liferay_commerce_product_definitions_web_internal_pโ€ฆ

๐Ÿ“… Published: Sept. 24, 2025, 12:56 a.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 6:19 p.m.

6.4

CVSS3.1

CVE-2025-60020 -

nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.

๐Ÿ“… Published: Sept. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-57354 -

A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user-controlled input in translation key processing. The affected versions prior to 0.18.6 allow attackers to manipulate the library's translation functionality by supplying maliciousโ€ฆ

๐Ÿ“… Published: Sept. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-57349 -

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key paths in versions prior to 2.3.0. The flaw arises when processing nested message keys containing special characters โ€ฆ

๐Ÿ“… Published: Sept. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 17, 2025, 2:49 p.m.

9.8

CVSS3.1

CVE-2025-57347 -

A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConflict function, which fails to properly sanitize user-supplied input during property assignment operations. This flaw allows attackers to exploit prototype pollution vulnerabilitieโ€ฆ

๐Ÿ“… Published: Sept. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 17, 2025, 2:53 p.m.
Total resulsts: 349182
Page 3700 of 34,919
ยซ previous page ยป next page
Filters