7.4

CVSS3.1

CVE-2025-2697 - IBM Cognos Command Center HTTP Open Redirect

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to…

πŸ“… Published: Aug. 26, 2025, 4:47 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:06 p.m.

6.1

CVSS3.1

CVE-2025-1494 - IBM Cognos Command Center clickjacking

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks …

πŸ“… Published: Aug. 26, 2025, 4:45 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:07 p.m.

3.7

CVSS3.1

CVE-2025-55212 - ImageMagick affected by divide-by-zero in ThumbnailImage via montage -geometry ":" leads to crash

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (":") to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these…

πŸ“… Published: Aug. 26, 2025, 4:43 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:16 p.m.

7.2

CVSS3.1

CVE-2025-36729 - RACOM M!DGE2 Privilege Escalation via SDK Testing Endpoint

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.

πŸ“… Published: Aug. 26, 2025, 4:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2025-9491 - Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malici…

πŸ“… Published: Aug. 26, 2025, 4:25 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 4:28 p.m.

5.9

CVSS3.1

CVE-2025-57813 - Insertion of Sensitive Information into Log File in github.com/traPtitech/traQ

traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, such as OAuth tokens, are recorded in log files when an error occurs during the execution of an SQL query. An attacker could intentionally trigger an SQ…

πŸ“… Published: Aug. 26, 2025, 4:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-57810 - jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS)

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful PNG fil…

πŸ“… Published: Aug. 26, 2025, 3:37 p.m. πŸ”„ Last Modified: Sept. 9, 2025, 6:56 p.m.

8.8

CVSS3.1

CVE-2025-6366 - Event List <= 2.0.4 - Authenticated (Subscriber+) Privilege Escalation

The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly validating a user's capabilities prior to updating their profile in the el_update_profile() function. This makes it possible for authenticate…

πŸ“… Published: Aug. 26, 2025, 2:26 p.m. πŸ”„ Last Modified: April 22, 2026, 4:15 a.m.

8.7

CVSS4.0

CVE-2025-9483 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 singlePortForwardAdd stack-based overflow

A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function singlePortForwardAdd of the file /goform/singlePortForwardAdd. This manipulation of the argument ruleName/schedule/inboundFilter cause…

πŸ“… Published: Aug. 26, 2025, 2:02 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:08 p.m.

8.7

CVSS4.0

CVE-2025-9482 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 portRangeForwardAdd stack-based overflow

A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts the function portRangeForwardAdd of the file /goform/portRangeForwardAdd. The manipulation of the argument ruleName/schedule/inboundFilter/…

πŸ“… Published: Aug. 26, 2025, 1:32 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:08 p.m.
Total resulsts: 349182
Page 4134 of 34,919
Β« previous page Β» next page
Filters