7.5

CVSS3.1

CVE-2025-58144 - Arm issues with page refcounting

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wrong there, where the case actually needs handling. A NULL po…

📅 Published: Sept. 11, 2025, 2:05 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.4

CVSS4.0

CVE-2025-10193 - Neo4j Cypher MCP server is vulnerable to DNS rebinding attacks

DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend suffici…

📅 Published: Sept. 11, 2025, 2:05 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-58143 - Mutiple vulnerabilities in the Viridian interface

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the refere…

📅 Published: Sept. 11, 2025, 2:05 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

9.8

CVSS3.1

CVE-2025-58142 - Mutiple vulnerabilities in the Viridian interface

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the refere…

📅 Published: Sept. 11, 2025, 2:05 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

9.8

CVSS3.1

CVE-2025-27466 - Mutiple vulnerabilities in the Viridian interface

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the refere…

📅 Published: Sept. 11, 2025, 2:05 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

5.1

CVSS4.0

CVE-2025-10253 - openDCIM SVG File uploadifive.php cross site scripting

A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifive.php of the component SVG File Handler. Such manipulation of the argument Filedata leads to cross site scripting. The attack can be launched remotely. The exploit has been discl…

📅 Published: Sept. 11, 2025, 2:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS4.0

CVE-2025-8716 - Cache exploitation vulnerability

In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to download unprotected files from the server if the filenames are known.

📅 Published: Sept. 11, 2025, 1:42 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2025-10252 - SEAT Queue Ticket Kiosk Java RMI Registry deserialization

A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. The attack can only be done within the local network. The attack is considered to have high complexity. It is indicated…

📅 Published: Sept. 11, 2025, 1:32 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10251 - FoxCMS Images.php batchCope sql injection

A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/admin/controller/Images.php. The manipulation of the argument ids results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. T…

📅 Published: Sept. 11, 2025, 1:02 p.m. 🔄 Last Modified: Oct. 2, 2025, 7:38 p.m.

8

CVSS3.1

CVE-2025-58060 - cups has Authentication bypass with AuthType Negotiate

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authent…

📅 Published: Sept. 11, 2025, 1 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.
Total resulsts: 349182
Page 3901 of 34,919
« previous page » next page
Filters