5.4

CVSS4.0

CVE-2025-20048 -

Uncontrolled search path for the Intel(R) Trace Analyzer and Collector software all verions may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“… Published: Aug. 12, 2025, 4:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-20037 -

Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of privilege via local access.

πŸ“… Published: Aug. 12, 2025, 4:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.1

CVSS4.0

CVE-2025-20025 -

Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticated user to potentially enable denial of service via local access.

πŸ“… Published: Aug. 12, 2025, 4:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS4.0

CVE-2025-20023 -

Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“… Published: Aug. 12, 2025, 4:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS4.0

CVE-2025-20017 -

Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“… Published: Aug. 12, 2025, 4:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-55167 - WeGIA SQL Injection via id_fichamedica at endpoint `GET/html/funcionario/dependente_remover.php`

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_remover.php endpoint, specifically in the id_dependente parameter. This vulnerability all…

πŸ“… Published: Aug. 12, 2025, 4:33 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 3:36 p.m.

5.1

CVSS4.0

CVE-2025-55166 - svg-sanitizer By-Passing Attribute Sanitization

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method only searches for lower-case attribute name, which allows to by-pass the isHrefSafeValue check. As a result this allows cross-site scripting or linking to external domains. This …

πŸ“… Published: Aug. 12, 2025, 4:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-3089 - Broken Access Control in ServiceNow AI Platform

ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a low privileged user to bypass access controls and perform a limited set of actions typically reserved for higher privileged users, potentially leading t…

πŸ“… Published: Aug. 12, 2025, 4:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-55164 - content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE

content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one can override the Object prototype. This issue has been patched in version 0.6.0. A workaround involve…

πŸ“… Published: Aug. 12, 2025, 4:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-5187 - Nodes can delete themselves by adding an OwnerReference

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted,…

πŸ“… Published: Aug. 12, 2025, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348618
Page 4281 of 34,862
Β« previous page Β» next page
Filters