8.1

CVSS3.1

CVE-2025-8309 - User privilege escalation vulnerability

There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, Service…

πŸ“… Published: Aug. 20, 2025, 4:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-46962 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

πŸ“… Published: Aug. 20, 2025, 4:50 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 2:20 p.m.

7

CVSS4.0

CVE-2025-6183 - Configd Injection

The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a malicious JSON message.

πŸ“… Published: Aug. 20, 2025, 4:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-6182 - Root Certificate Injection

The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.

πŸ“… Published: Aug. 20, 2025, 4:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-46998 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

πŸ“… Published: Aug. 20, 2025, 4:44 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 2:20 p.m.

8.5

CVSS4.0

CVE-2025-6181 -

The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

πŸ“… Published: Aug. 20, 2025, 4:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-6180 - Authentication Hijack

The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.

πŸ“… Published: Aug. 20, 2025, 4:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2010-20010 - Foxit PDF Reader < 4.2.0.0928 Title Stack Buffer Overflow

Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in t…

πŸ“… Published: Aug. 20, 2025, 4:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-57827 -

Not used

πŸ“… Published: Aug. 20, 2025, 4:29 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 2:55 a.m.

0.0

CVE-2025-57826 -

Not used

πŸ“… Published: Aug. 20, 2025, 4:29 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 2:55 a.m.
Total resulsts: 349182
Page 4194 of 34,919
Β« previous page Β» next page
Filters