5.6

CVSS3.1

CVE-2025-47182 - Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

📅 Published: July 11, 2025, 4:36 p.m. 🔄 Last Modified: Feb. 20, 2026, 4:01 p.m.

8.2

CVSS3.1

CVE-2025-7026 - SMM Arbitrary Write via Unchecked RBX Pointer in CommandRcx0

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer in the CommandRcx0 function. If the contents at RBX match certain expected values (e.g., '$DB$' or '2DB$'), the function performs arbitrary w…

📅 Published: July 11, 2025, 3:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-7028 - SMM Arbitrary Memory Access via Flash Handler with Unchecked FuncBlock Pointer

A vulnerability in the Software SMI handler (SwSmiInputValue 0x20) allows a local attacker to supply a crafted pointer (FuncBlock) through RBX and RCX register values. This pointer is passed unchecked into multiple flash management functions (ReadFlash, WriteFlash, EraseFlash, and GetFlashInfo) tha…

📅 Published: July 11, 2025, 3:26 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-7027 - SMM Arbitrary Write via Dual-Controlled Pointers in CommandRcx1

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control both the read and write addresses used by the CommandRcx1 function. The write target is derived from an unvalidated UEFI NVRAM variable (SetupXtuBufferAddress), while the write content is read from…

📅 Published: July 11, 2025, 3:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-7029 - SMM Arbitrary Write via Unchecked OcHeader Buffer in Platform Configuration Handler

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHeader, OcData) passed into power and thermal configuration logic. These buffers are not validated before performing multiple structured memory…

📅 Published: July 11, 2025, 3:22 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2025-52988 - Junos OS and Junos OS Evolved: Privilege escalation to root via CLI command 'request system logout'

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a high privileged, local attacker to escalated their privileges to root. When a user provides specifically crafted argumen…

📅 Published: July 11, 2025, 3:11 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:50 p.m.

6.9

CVSS4.0

CVE-2025-6549 - Junos OS: SRX Series: J-Web can be exposed on additional interfaces

An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the Juniper Web Device Manager (J-Web). When Juniper Secure connect (JSC) is enabled on specific interfaces, or multiple interfaces a…

📅 Published: July 11, 2025, 3:11 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:18 p.m.

6.8

CVSS4.0

CVE-2025-52989 - Junos OS and Junos OS Evolved: Annotate configuration command can be used to change the configurati…

An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit permissions, using a specifically crafte…

📅 Published: July 11, 2025, 3:10 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:18 p.m.

6.8

CVSS4.0

CVE-2025-52986 - Junos OS and Junos OS Evolved: When RIB sharding is configured each time a show command is executed…

A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low privileged user to cause an impact to the availability of the device. When RIB sharding is enabled and a user executes one o…

📅 Published: July 11, 2025, 3:10 p.m. 🔄 Last Modified: Jan. 30, 2026, 8:42 p.m.

6.9

CVSS4.0

CVE-2025-52985 - Junos OS Evolved: When a control-plane firewall filter refers to a prefix-list with more than 10 en…

A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass security restrictions. When a firewall filter which is applied to the lo0 or re:mgmt interface references a prefix list with 'f…

📅 Published: July 11, 2025, 3:09 p.m. 🔄 Last Modified: Jan. 23, 2026, 5:06 p.m.
Total resulsts: 345234
Page 4277 of 34,524
« previous page » next page
Filters