8.5

CVSS4.0

CVE-2025-65109 - Minder does not sandbox http.send in Rego programs

Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access…

πŸ“… Published: Nov. 21, 2025, 9:56 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:56 p.m.

10

CVSS3.1

CVE-2025-65108 - md-to-pdf is vulnerable to arbitrary JavaScript code execution when parsing front matter

md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of …

πŸ“… Published: Nov. 21, 2025, 9:52 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:52 p.m.

6.5

CVSS3.1

CVE-2025-65107 - Langfuse SSO Account Takeover via CSRF or phishing attack

Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations without an explicit AUTH_<PROVIDER>_CHECK setting, a potential account takeover may happen if an authenticated user is ma…

πŸ“… Published: Nov. 21, 2025, 9:49 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:49 p.m.

8.3

CVSS4.0

CVE-2025-65106 - LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulnera…

πŸ“… Published: Nov. 21, 2025, 9:43 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:53 p.m.

8.7

CVSS4.0

CVE-2025-65102 - PJSIP is vulnerable to buffer overflow in Opus PLC

PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may be less than that. This issue affects PJSIP users who use the Opus audio co…

πŸ“… Published: Nov. 21, 2025, 9:36 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:36 p.m.

6.9

CVSS4.0

CVE-2025-65092 - ESP32-P4 JPEG Decoder Header Parsing Vulnerability

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the ESP32-P4 uses its hardware JPEG decoder, the software parser lacks necessary validation checks. A specially crafted (malicious) JPEG image could exploit the parsing routine and tri…

πŸ“… Published: Nov. 21, 2025, 9:33 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:33 p.m.

5.3

CVSS4.0

CVE-2025-0504 - Black Duck SCA Project Privilege Escalation

Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. E…

πŸ“… Published: Nov. 21, 2025, 9:30 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:30 p.m.

0.0

CVE-2025-31216 -

The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.

πŸ“… Published: Nov. 21, 2025, 9:22 p.m. πŸ”„ Last Modified: Nov. 23, 2025, 11:27 a.m.

0.0

CVE-2025-31266 -

A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.

πŸ“… Published: Nov. 21, 2025, 9:22 p.m. πŸ”„ Last Modified: Nov. 23, 2025, 11:32 a.m.

0.0

CVE-2025-43374 -

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, visionOS 2.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS Sequoia 15.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-bounds read …

πŸ“… Published: Nov. 21, 2025, 9:22 p.m. πŸ”„ Last Modified: Nov. 23, 2025, 11:29 a.m.
Total resulsts: 319147
Page 4 of 31,915
Β« previous page Β» next page
Filters