7.1

CVSS4.0

CVE-2025-59018 - Information Disclosure in Workspaces Module

Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.

📅 Published: Sept. 9, 2025, 9:01 a.m. 🔄 Last Modified: Sept. 26, 2025, 2:08 p.m.

5.3

CVSS4.0

CVE-2025-59017 - Broken Access Control in Backend AJAX Routes

Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.

📅 Published: Sept. 9, 2025, 9:01 a.m. 🔄 Last Modified: Sept. 10, 2025, 1:44 p.m.

5.3

CVSS4.0

CVE-2025-59016 - Information Disclosure via File Abstraction Layer

Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.

📅 Published: Sept. 9, 2025, 9 a.m. 🔄 Last Modified: Sept. 10, 2025, 1:43 p.m.

6.3

CVSS4.0

CVE-2025-59015 - Insufficient Entropy in Password Generation

A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.

📅 Published: Sept. 9, 2025, 9 a.m. 🔄 Last Modified: Sept. 10, 2025, 1:42 p.m.

5.1

CVSS4.0

CVE-2025-59014 - Denial of Service in TYPO3 Bookmark Toolbar

An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the backend user interface by saving manipulated data in the bookmark toolbar.

📅 Published: Sept. 9, 2025, 9 a.m. 🔄 Last Modified: Sept. 10, 2025, 1:40 p.m.

5.3

CVSS4.0

CVE-2025-59013 - Open Redirect in TYPO3 CMS

An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker to redirect users to arbitrary external sites, enabling phishing attacks by supplying a manipulated, sanitized URL.

📅 Published: Sept. 9, 2025, 9 a.m. 🔄 Last Modified: Sept. 10, 2025, 1:38 p.m.

7.8

CVSS3.1

CVE-2025-41701 - Beckhoff: Deserialization of untrusted data by TwinCAT 3 Engineering

An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affected engineering tool. These arbitrary commands are executed in the user context.

📅 Published: Sept. 9, 2025, 8:57 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-40804 -

A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization.

📅 Published: Sept. 9, 2025, 8:48 a.m. 🔄 Last Modified: Sept. 9, 2025, 9:31 p.m.

2.3

CVSS4.0

CVE-2025-40803 -

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical information from the device. This could allow an unauthenticated attacker to access sensitive data, potentially leading to a breach of confidentiality.

📅 Published: Sept. 9, 2025, 8:48 a.m. 🔄 Last Modified: Oct. 3, 2025, 7:36 p.m.

2.3

CVSS4.0

CVE-2025-40802 -

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to high volumes of query requests. This could allow an attacker to cause a temporary denial of service, with the system recovering …

📅 Published: Sept. 9, 2025, 8:48 a.m. 🔄 Last Modified: Oct. 3, 2025, 7:37 p.m.
Total resulsts: 349182
Page 3950 of 34,919
« previous page » next page
Filters