7.7

CVSS4.0

CVE-2025-34520 - Arcserve UDP < 10.2 Authentication Bypass

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a logic flaw, an attacker can bypass login mechanisms โ€ฆ

๐Ÿ“… Published: Aug. 27, 2025, 9:19 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 3:44 p.m.

4.8

CVSS4.0

CVE-2025-34521 - Arcserve UDP < 10.2 Reflected Cross-Site Scripting (XSS)

A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited bโ€ฆ

๐Ÿ“… Published: Aug. 27, 2025, 9:19 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 3:44 p.m.

9.2

CVSS4.0

CVE-2025-34522 - Arcserve UDP < 10.2 Pre-Authentication Heap Overflow

A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checking allows an attacker to overwrite heap memory, poโ€ฆ

๐Ÿ“… Published: Aug. 27, 2025, 9:19 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 3:44 p.m.

9.2

CVSS4.0

CVE-2025-34523 - Arcserve UDP < 10.2 Pre-Authentication Heap Overflow

A heap-based buffer overflow vulnerability exists in the exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw is reachable without authentication and results from improper bounds checking when processing attacker-controlled input. By sending specโ€ฆ

๐Ÿ“… Published: Aug. 27, 2025, 9:19 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 3:44 p.m.

7.5

CVSS3.1

CVE-2025-40779 - Kea crash upon interaction between specific client options and subnet selection

If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion failure. This happens only if the client request is unicast directly to Kea; broadcast messages do not cause the problem. โ€ฆ

๐Ÿ“… Published: Aug. 27, 2025, 8:23 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS3.1

CVE-2025-2246 - Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

๐Ÿ“… Published: Aug. 27, 2025, 7:34 p.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 5:49 p.m.

6.5

CVSS3.1

CVE-2025-3601 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large responses.

๐Ÿ“… Published: Aug. 27, 2025, 7:33 p.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 5:49 p.m.

5.3

CVSS3.1

CVE-2025-4225 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending specially cโ€ฆ

๐Ÿ“… Published: Aug. 27, 2025, 7:33 p.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 5:48 p.m.

5

CVSS3.1

CVE-2025-5101 - Improper Control of Generation of Code ('Code Injection') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambโ€ฆ

๐Ÿ“… Published: Aug. 27, 2025, 7:33 p.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 5:47 p.m.

6.9

CVSS4.0

CVE-2025-58050 - PCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCS

The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined wiโ€ฆ

๐Ÿ“… Published: Aug. 27, 2025, 6:47 p.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 3:27 p.m.
Total resulsts: 349182
Page 4117 of 34,919
ยซ previous page ยป next page
Filters