8.1

CVSS3.1

CVE-2025-58439 - ERP: Possibility of SQL injection due to missing validation

ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version could be retrieved. This issue is fixed in versions 1…

πŸ“… Published: Sept. 6, 2025, 12:30 a.m. πŸ”„ Last Modified: Oct. 27, 2025, 6:03 p.m.

7.9

CVSS3.1

CVE-2021-26383 -

Insufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised userspace to invoke a command with malformed arguments leading to out of bounds memory access, potentially resulting in loss of integrity or availability.

πŸ“… Published: Sept. 5, 2025, 11:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-58373 - Roo Code: Symlink-bypass of .rooignore can lead to unintended file disclosure

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed using symlinks. This allows an attacker with write access to the workspace to trick the extension into reading files that…

πŸ“… Published: Sept. 5, 2025, 10:55 p.m. πŸ”„ Last Modified: Sept. 15, 2025, 6:08 p.m.

8.1

CVSS3.1

CVE-2025-58372 - Roo Code: Potential Remote Code Execution via .code-workspace

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace configuration files (.code-workspace) are not protected in the same way as the .vscode folder. If the agent was configured to auto-appro…

πŸ“… Published: Sept. 5, 2025, 10:51 p.m. πŸ”„ Last Modified: Sept. 15, 2025, 6:08 p.m.

9.9

CVSS4.0

CVE-2025-58371 - Roo Code is vulnerable to command injection via GitHub actions workflow

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request metadata in a privileged context, allowing an attacker to craft malicious input and achieve Remote Code Execution (RCE) on the Actions runner…

πŸ“… Published: Sept. 5, 2025, 10:42 p.m. πŸ”„ Last Modified: Sept. 15, 2025, 6:08 p.m.

8.1

CVSS3.1

CVE-2025-58370 - Roo Code: Potential Remote Code Execution via Bash Parameter Expansion and Indirect Reference

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where the Bash parameter expansion and indirect reference were not handled correctly. If the agent was configured to auto-approve execution of c…

πŸ“… Published: Sept. 5, 2025, 10:09 p.m. πŸ”„ Last Modified: Sept. 10, 2025, 3:11 p.m.

5.3

CVSS3.1

CVE-2025-58369 - fs2: Half-shutdown of socket during TLS handshake may result in spin loop on opposite side

fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, and 3.13.0-M1 through 3.13.0-M6 are vulnerable to denial of service attacks though TLS sessions using fs2-io on the JVM using the fs2.io.net.tls package. When establishing a TLS se…

πŸ“… Published: Sept. 5, 2025, 9:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-58367 - DeepDiff is vulnerable to DoS and Remote Code Execution via Delta class pollution

DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnerable to class pollution via the Delta class constructor, and when combined with a gadget available in DeltaDiff, it can lead to Denial of Service and Remote Code Execution (via ins…

πŸ“… Published: Sept. 5, 2025, 9:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-10027 - itsourcecode POS Point of Sale System 2512.php cross site scripting

A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This manipulation of the argument scripts causes cross site scripting. The attack can be …

πŸ“… Published: Sept. 5, 2025, 9:32 p.m. πŸ”„ Last Modified: Sept. 10, 2025, 3:56 p.m.

9.4

CVSS4.0

CVE-2025-58366 - Onyxia private helm repository credentials are leaked through unauthenticated API

Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the cata…

πŸ“… Published: Sept. 5, 2025, 9:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3976 of 34,919
Β« previous page Β» next page
Filters