8.8

CVSS3.1

CVE-2025-55319 - Agentic AI and Visual Studio Code Remote Code Execution Vulnerability

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.

πŸ“… Published: Sept. 12, 2025, 12:49 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

5.3

CVSS4.0

CVE-2025-10274 - erjinzhi 10OA item cross site scripting

A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the file /trial/mvc/item. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public…

πŸ“… Published: Sept. 12, 2025, 12:02 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 7:23 p.m.

5.3

CVSS3.1

CVE-2024-45431 -

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper validation of remote L2CAP channel ID (CID). An attacker can leverage this to create an L2CAP channel with the null id…

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 8:03 p.m.

5.5

CVSS3.1

CVE-2025-39795 - block: avoid possible overflow for chunk_sectors check in blk_stack_limits()

In the Linux kernel, the following vulnerability has been resolved: block: avoid possible overflow for chunk_sectors check in blk_stack_limits() In blk_stack_limits(), we check that the t->chunk_sectors value is a multiple of the t->physical_block_size value. However, by finding the chunk_sector…

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8 p.m.

8

CVSS3.1

CVE-2025-57577 -

An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a case of misconfigura…

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-45583 -

Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:39 p.m.

6.3

CVSS3.1

CVE-2025-55996 -

Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:54 p.m.

6.5

CVSS3.1

CVE-2025-56467 -

An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended featu…

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2025-45587 -

A stack overflow in the FTP service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:30 p.m.

6.5

CVSS3.1

CVE-2024-45433 -

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper return control flow after detecting an unusual condition. An attacker can leverage this to bypass a security vali…

πŸ“… Published: Sept. 12, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 8:02 p.m.
Total resulsts: 349182
Page 3896 of 34,919
Β« previous page Β» next page
Filters