6.5

CVSS3.1

CVE-2025-54995 - Asterisk remotely exploitable leak of RTP UDP ports and internal resources

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.…

πŸ“… Published: Aug. 28, 2025, 3:08 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 6:17 p.m.

6.9

CVSS4.0

CVE-2024-48908 - lychee-action vulnerable to arbitrary code injection in composite action

lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. This issue has been patched in version 2.0.2.

πŸ“… Published: Aug. 28, 2025, 2:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2025-8067 - Udisks: out-of-bounds read in udisks daemon

A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the parameters of this handle, it receives the file descriptor li…

πŸ“… Published: Aug. 28, 2025, 2:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-49790 - IBM Watson Studio on Cloud Pak for Data cross-site scripting

IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: Aug. 28, 2025, 2:09 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 4:31 p.m.

7.8

CVSS3.0

CVE-2025-9578 -

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 40734.

πŸ“… Published: Aug. 28, 2025, 2:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-58127 - Lack of TLS validation in plugin Dell Powerscale on Checkmk Exchange

Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercept traffic.

πŸ“… Published: Aug. 28, 2025, 12:59 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 3:41 p.m.

6.9

CVSS4.0

CVE-2025-58126 - Lack of TLS validation in plugin VMware vSAN on Checkmk Exchange

Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept traffic.

πŸ“… Published: Aug. 28, 2025, 12:59 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 3:49 p.m.

6.9

CVSS4.0

CVE-2025-58125 - Lack of TLS validation in plugin Freebox v6 agent on Checkmk Exchange

Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to intercept traffic.

πŸ“… Published: Aug. 28, 2025, 12:59 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 3:56 p.m.

6.9

CVSS4.0

CVE-2025-58124 - Lack of TLS validation in plugin check-mk-api on Checkmk Exchange

Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.

πŸ“… Published: Aug. 28, 2025, 12:59 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 9:33 a.m.

6.9

CVSS4.0

CVE-2025-58123 - Lack of TLS validation in plugin BGP Monitoring on Checkmk Exchange

Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.

πŸ“… Published: Aug. 28, 2025, 12:59 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:14 p.m.
Total resulsts: 349182
Page 4100 of 34,919
Β« previous page Β» next page
Filters