7.3

CVSS3.1

CVE-2025-54595 - Pearcleaner's unauthenticated access to privileged XPC helper allows root command execution

Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged helper tool bundled with the Pearcleaner application. It is registered and activated only after the user approves a system prompt to allow privileged operations. Upon approval, the …

📅 Published: Aug. 1, 2025, 6:06 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:21 p.m.

7.2

CVSS3.1

CVE-2025-54593 - FreshRSS is vulnerable to RCE attacks by authenticated admin

FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the FreshRSS server by modifying the update URL to one they control, and gain code execution after running an update. After successfully executing code, …

📅 Published: Aug. 1, 2025, 6:04 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:32 p.m.

5.7

CVSS3.1

CVE-2025-6015 - Vault Login MFA Bypass of Rate Limiting and TOTP Code Reuse

Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

📅 Published: Aug. 1, 2025, 6:03 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:35 p.m.

6.9

CVSS4.0

CVE-2025-54590 - webfinger.js is vulnerable to Blind SSRF attacks through localhost

webfinger.js is a TypeScript-based WebFinger client that runs in both browsers and Node.js environments. In versions 2.8.0 and below, the lookup function accepts user addresses for account checking. However, the ActivityPub specification requires preventing access to localhost services in productio…

📅 Published: Aug. 1, 2025, 6:03 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:39 p.m.

9.3

CVSS3.1

CVE-2025-54574 - Squid's URN Handling can lead to Buffer Overflow

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissi…

📅 Published: Aug. 1, 2025, 6:02 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:43 p.m.

5.5

CVSS4.0

CVE-2025-53012 - MaterialX's Lack of Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, nested imports of MaterialX files can lead to a crash via stack memory exhaustion, due to the lack of a limit on the "import chain" depth. When parsing …

📅 Published: Aug. 1, 2025, 6 p.m. 🔄 Last Modified: Aug. 1, 2025, 7:04 p.m.

3.7

CVSS3.1

CVE-2025-6011 - Timing Side-Channel in Vault’s Userpass Auth Method

A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1…

📅 Published: Aug. 1, 2025, 6 p.m. 🔄 Last Modified: Aug. 1, 2025, 7:06 p.m.

2

CVSS4.0

CVE-2025-53011 - MaterialX is Vulnerable to NULL Pointer Dereference due to Unchecked implGraphOutput

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted…

📅 Published: Aug. 1, 2025, 5:58 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:16 p.m.

2

CVSS4.0

CVE-2025-53010 - MaterialX's unchecked nodeGraph->getOutput return is vulnerable to NULL Pointer Dereference

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted…

📅 Published: Aug. 1, 2025, 5:58 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:19 p.m.

5.5

CVSS4.0

CVE-2025-53009 - MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing an MTLX file with multiple nested nodegraph implementations, the MaterialX XML parsing logic can potentially crash due to stack …

📅 Published: Aug. 1, 2025, 5:57 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:22 p.m.
Total resulsts: 303993
Page 4 of 30,400
« previous page » next page
Filters