5

CVSS3.1

CVE-2025-43938 -

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able …

πŸ“… Published: Sept. 10, 2025, 4:03 p.m. πŸ”„ Last Modified: Oct. 20, 2025, 2:02 p.m.

4.6

CVSS3.1

CVE-2025-59035 - Indico vulnerable to Cross-Site Scripting via LaTeX math code

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, there is a Cross-Site-Scripting vulnerability when rendering LaTeX math code in contribution or abstract descriptions. Users should to update to Indico 3.3.8 as s…

πŸ“… Published: Sept. 10, 2025, 4:03 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 9:23 p.m.

4.3

CVSS3.1

CVE-2025-59034 - Indico may disclose unauthorized user details access via legacy API

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check. U…

πŸ“… Published: Sept. 10, 2025, 4:01 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 9:31 p.m.

5.5

CVSS3.1

CVE-2025-8681 - Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interf…

Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Β Requires a high privileged user with a developer role.

πŸ“… Published: Sept. 10, 2025, 4 p.m. πŸ”„ Last Modified: Oct. 29, 2025, 6:14 p.m.

7

CVSS3.1

CVE-2025-43887 -

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: Sept. 10, 2025, 3:59 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

7.8

CVSS3.1

CVE-2025-43725 -

Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

πŸ“… Published: Sept. 10, 2025, 3:56 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

7.8

CVSS3.1

CVE-2025-43885 -

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command ex…

πŸ“… Published: Sept. 10, 2025, 3:52 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

8.2

CVSS3.1

CVE-2025-43884 -

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command e…

πŸ“… Published: Sept. 10, 2025, 3:47 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

8.8

CVSS3.1

CVE-2025-43888 -

Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

πŸ“… Published: Sept. 10, 2025, 3:42 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

8.7

CVSS4.0

CVE-2025-59041 - Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email

Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`. Prior to version 1.0.105, a maliciously configured user email in git could be used to trigger arbitrary code execution before a user accepted the workspace trust dialog. User…

πŸ“… Published: Sept. 10, 2025, 3:07 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 6:40 p.m.
Total resulsts: 349182
Page 3917 of 34,919
Β« previous page Β» next page
Filters