8.4

CVSS4.0

CVE-2025-58400 -

RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

πŸ“… Published: Sept. 5, 2025, 5:36 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-41408 -

Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim of a phishing attack.

πŸ“… Published: Sept. 5, 2025, 5:25 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-55671 -

Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be executed with the privilege of running the program.

πŸ“… Published: Sept. 5, 2025, 5:24 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-55037 -

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote unauthenticated attacker if the settings are configured to construc…

πŸ“… Published: Sept. 5, 2025, 5:24 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-58401 -

Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.

πŸ“… Published: Sept. 5, 2025, 4:28 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-8684 - Flatsome <= 3.20.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with cont…

πŸ“… Published: Sept. 5, 2025, 3:25 a.m. πŸ”„ Last Modified: April 20, 2026, 10 p.m.

6.5

CVSS3.1

CVE-2025-7445 - Kubernetes secrets-store-sync-controller discloses service account tokens in logs

Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.

πŸ“… Published: Sept. 5, 2025, 2:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-9990 - WordPress Helpdesk Integration <= 5.8.10 - Unauthenticated Local File Inclusion

The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the exec…

πŸ“… Published: Sept. 5, 2025, 2:25 a.m. πŸ”„ Last Modified: April 21, 2026, 3:30 a.m.

7.8

CVSS3.1

CVE-2025-39717 - open_tree_attr: do not allow id-mapping changes without OPEN_TREE_CLONE

In the Linux kernel, the following vulnerability has been resolved: open_tree_attr: do not allow id-mapping changes without OPEN_TREE_CLONE As described in commit 7a54947e727b ('Merge patch series "fs: allow changing idmappings"'), open_tree_attr(2) was necessary in order to allow for a detached …

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 5:48 p.m.

7.0

CVSS3.1

CVE-2025-39702 - ipv6: sr: Fix MAC comparison to be constant-time

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:25 p.m.
Total resulsts: 349182
Page 3993 of 34,919
Β« previous page Β» next page
Filters