9.3

CVSS4.0

CVE-2025-34203 - Vasion Print (formerly PrinterLogic) Use of Outdated, End-Of-Life, and Vulnerable Third-Party Compo…

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior toΒ 20.0.2614Β (VA and SaaS deployments) contain multiple Docker containers that include outdated, end-of-life, unsupported, or otherwise vulnerable third-party components (examples:…

πŸ“… Published: Sept. 19, 2025, 6:36 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 11:56 p.m.

7.5

CVSS3.1

CVE-2025-26515 - CVE-2025-26515 Server-Side Request Forgery Vulnerability in StorageGRID (formerly StorageGRID Websc…

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an unauthenticated attacker to change the password of any Grid Manager or Ten…

πŸ“… Published: Sept. 19, 2025, 6:34 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:31 p.m.

6.4

CVSS3.1

CVE-2025-26514 - CVE-2025-26514 Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID We…

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker t…

πŸ“… Published: Sept. 19, 2025, 6:31 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:32 p.m.

4.8

CVSS4.0

CVE-2025-10722 - SKTLab Mukbee App com.dw.android.mukbee AndroidManifest.xml improper export of android application …

A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file AndroidManifest.xml of the component com.dw.android.mukbee. The manipulation results in improper export of android application components. The attack must be initiated from a local po…

πŸ“… Published: Sept. 19, 2025, 5:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-10721 - Webull Investing & Trading App AndroidManifest.xml improper export of android application components

A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml. This manipulation causes improper export of android application components. The attack can only be executed locally. The exploit has been p…

πŸ“… Published: Sept. 19, 2025, 5:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-36248 - IBM Copy Services Manager cross-site scripting

IBM Copy Services Manager 6.3.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: Sept. 19, 2025, 4:22 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 7:07 p.m.

4.8

CVSS4.0

CVE-2025-10718 - Ooma Office Business Phone App com.ooma.office2 improper export of android application components

A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The manipulation results in improper export of android application components. The attack needs to be approached locally. The exploit has been made pub…

πŸ“… Published: Sept. 19, 2025, 4:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.9

CVSS4.0

CVE-2025-59427 - Cloudflare vite plugin exposes secrets over the built-in dev server

The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .…

πŸ“… Published: Sept. 19, 2025, 3:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-39862 - wifi: mt76: mt7915: fix list corruption after hardware restart

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix list corruption after hardware restart Since stations are recreated from scratch, all lists that wcids are added to must be cleared before calling ieee80211_restart_hw. Set wcid->sta = 0 for each wcid entr…

πŸ“… Published: Sept. 19, 2025, 3:26 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

7.8

CVSS3.1

CVE-2025-39860 - Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() syzbot reported the splat below without a repro. In the splat, a single thread calling bt_accept_dequeue() freed sk and touched it after that. The root cause would be…

πŸ“… Published: Sept. 19, 2025, 3:26 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 8:42 p.m.
Total resulsts: 349182
Page 3766 of 34,919
Β« previous page Β» next page
Filters