8.8

CVSS4.0

CVE-2025-7774 - Rockwell Automation ArmorBlock 5000 I/O – Web Server Vulnerabilities

A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials can be used within a 3-minute timeout window, allowing unauthorized users to perform privileged actions.

📅 Published: Aug. 14, 2025, 1:39 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-9036 - Rockwell Automation FactoryTalk® Action Manager v1.0.0 Runtime Vulnerability

A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the connection.

📅 Published: Aug. 14, 2025, 1:39 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-7353 - Rockwell Automation ControlLogix® Ethernet Remote Code Execution Vulnerability

A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Modules. If a specific IP address is used to connect to the WDB agent, it can allow remote attackers to perform memory dumps, modify memory, and control execution flow.

📅 Published: Aug. 14, 2025, 1:23 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-55675 - Apache Superset: Incorrect datasource authorization on REST API

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL, an attacker can enu…

📅 Published: Aug. 14, 2025, 1:18 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-55674 - Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended to be disabled, leadi…

📅 Published: Aug. 14, 2025, 1:18 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-55672 - Apache Superset: Stored XSS on charts metadata

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they ho…

📅 Published: Aug. 14, 2025, 1:17 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-55673 - Apache Superset: Metadata exposure in embedded charts

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user. This…

📅 Published: Aug. 14, 2025, 1:16 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

4.1

CVSS3.1

CVE-2023-5342 - Shim: expired secure boot certificate

The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.

📅 Published: Aug. 14, 2025, 1:15 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-8963 - jeecgboot JimuReport Data Large Screen Template testConnection deserialization

A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. Th…

📅 Published: Aug. 14, 2025, 1:02 p.m. 🔄 Last Modified: Oct. 17, 2025, 5:55 p.m.

8.8

CVSS3.1

CVE-2025-8715 - PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore tar…

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks…

📅 Published: Aug. 14, 2025, 1 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348389
Page 4198 of 34,839
« previous page » next page
Filters