7.5

CVSS3.1

CVE-2025-64173 - Apollo Router Core: Access Control Bypass on Polymorphic Types

Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation 2. In versions 1.61.11 below, as well as 2.0.0-alpha.0 through 2.8.1-rc.0, a vulnerability allowed for unauthenticated queries to access data that required additional access contr…

📅 Published: Nov. 6, 2025, 8:42 p.m. 🔄 Last Modified: Nov. 6, 2025, 8:42 p.m.

8.8

CVSS3.0

CVE-2025-12486 - Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability

Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Minimal user interaction is required to exploit this vulnerability. The specific fl…

📅 Published: Nov. 6, 2025, 8:12 p.m. 🔄 Last Modified: Nov. 6, 2025, 8:12 p.m.

9.8

CVSS3.0

CVE-2025-12487 - oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Executio…

oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulne…

📅 Published: Nov. 6, 2025, 8:12 p.m. 🔄 Last Modified: Nov. 6, 2025, 8:12 p.m.

9.8

CVSS3.0

CVE-2025-12488 - oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Executio…

oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulne…

📅 Published: Nov. 6, 2025, 8:11 p.m. 🔄 Last Modified: Nov. 6, 2025, 8:11 p.m.

7.8

CVSS3.0

CVE-2025-12489 - evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability

evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of evernote-mcp-server. An attacker must first obtain the ability to execute low-privileged code on the target system in o…

📅 Published: Nov. 6, 2025, 8:11 p.m. 🔄 Last Modified: Nov. 6, 2025, 8:11 p.m.

8.8

CVSS3.0

CVE-2025-12490 - Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability

Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Netgate pfSense. Authentication is required to exploit this vulnerability. The specific flaw exists within the Suricata …

📅 Published: Nov. 6, 2025, 8:10 p.m. 🔄 Last Modified: Nov. 6, 2025, 8:10 p.m.

8.8

CVSS4.0

CVE-2022-50590 - SuiteCRM < 7.12.6 Type Confusion via 'deleteAttachment' Functionality

SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the…

📅 Published: Nov. 6, 2025, 7:59 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:59 p.m.

9.3

CVSS4.0

CVE-2022-50589 - SuiteCRM < 7.12.6 SQL Injection via 'export' Functionality

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.

📅 Published: Nov. 6, 2025, 7:59 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:59 p.m.

9.3

CVSS4.0

CVE-2022-50596 - D-Link DIR-1260 <= v1.20B05 GetDeviceSettings Unauthenticated Command Injection

D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management interface that allows for unauthenticated attackers to execute arbitrary commands on the device with root privileges. The flaw specifically exists within t…

📅 Published: Nov. 6, 2025, 7:58 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:58 p.m.

9.3

CVSS4.0

CVE-2022-50595 - Advantech iView < v5.7.04 Build 6425 ztp_search_value Parameter SQL Injection RCE

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_search_value’ parameter to the ‘NetworkServlet’ endpoint. Successful …

📅 Published: Nov. 6, 2025, 7:58 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:58 p.m.
Total resulsts: 317272
Page 4 of 31,728
« previous page » next page
Filters