8.6

CVSS4.0

CVE-2025-59037 - DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware

DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of DuckDB's packages that included malicious code to interโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:26 p.m. ๐Ÿ”„ Last Modified: Sept. 12, 2025, 9:11 a.m.

5.1

CVSS4.0

CVE-2025-34178 - Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scripting

In pfSense CEย /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricataโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:23 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 12:22 p.m.

9.7

CVSS3.1

CVE-2025-58768 - DeepChat's Mermaid rendering has XSS leading to RCE

DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `innerHTML` to set user content. Therefore, any malicious content rendered via Mermaid will directly trigger the exploit chain, โ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:19 p.m. ๐Ÿ”„ Last Modified: Sept. 18, 2025, 8:26 p.m.

5.1

CVSS4.0

CVE-2025-34177 - Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scripting

In pfSense CEย /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricataโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:19 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 12:23 p.m.

7.1

CVSS3.1

CVE-2025-58765 - wabac.js has XSS vulnerability in 404 error handling logic

wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the 404 error handling logic of wabac.js v2.23.10 and below. The parameter `requestURL` (derived from the original request target) is direcโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:16 p.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 5:14 p.m.

5.3

CVSS4.0

CVE-2025-34176 - Netgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information Disclosure

In pfSense CEย /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the fiโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:14 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 12:23 p.m.

8.1

CVSS3.1

CVE-2025-58763 - Tautulli vulnerable to Authenticated Remote Code Execution via Command Injection

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows attackers with administrative privileges to obtain remote code execution on the application server. This vulnerability requires the application to haโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:13 p.m. ๐Ÿ”„ Last Modified: Sept. 18, 2025, 8:30 p.m.

4

CVSS3.1

CVE-2025-54255 - Acrobat Reader | Violation of Secure Design Principles (CWE-657)

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An attacker does not have to be authenticated. Exploitation of this issue does not rโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:10 p.m. ๐Ÿ”„ Last Modified: Oct. 2, 2025, 2:43 p.m.

5.1

CVSS4.0

CVE-2025-34175 - Netgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site Scripting

In pfSense CEย /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated.

๐Ÿ“… Published: Sept. 9, 2025, 8:09 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 12:23 p.m.

7.8

CVSS3.1

CVE-2025-54257 - Acrobat Reader | Use After Free (CWE-416)

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:08 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.
Total resulsts: 349182
Page 3928 of 34,919
ยซ previous page ยป next page
Filters