7.8

CVSS3.1

CVE-2025-43594 - InDesign Desktop | Out-of-bounds Write (CWE-787)

InDesign Desktop versions 19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐Ÿ“… Published: July 8, 2025, 9:49 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.8

CVSS3.1

CVE-2025-47134 - InDesign Desktop | Heap-based Buffer Overflow (CWE-122)

InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐Ÿ“… Published: July 8, 2025, 9:49 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

7.8

CVSS3.1

CVE-2025-47136 - InDesign Desktop | Integer Underflow (Wrap or Wraparound) (CWE-191)

InDesign Desktop versions 19.5.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐Ÿ“… Published: July 8, 2025, 9:49 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

7.8

CVSS3.1

CVE-2025-47103 - InDesign Desktop | Heap-based Buffer Overflow (CWE-122)

InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐Ÿ“… Published: July 8, 2025, 9:48 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

7.3

CVSS4.0

CVE-2025-6759 - Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges

Local Privilege escalation allows a low-privileged user to gain SYSTEM privilegesย in Windows Virtual Delivery Agent for CVAD and Citrix DaaS

๐Ÿ“… Published: July 8, 2025, 9:41 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

5.4

CVSS3.1

CVE-2025-49547 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browโ€ฆ

๐Ÿ“… Published: July 8, 2025, 9:40 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 6:06 p.m.

5.4

CVSS3.1

CVE-2025-49534 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browโ€ฆ

๐Ÿ“… Published: July 8, 2025, 9:40 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 6:08 p.m.

8.5

CVSS3.1

CVE-2025-53547 - Helm Chart Dependency Updating With Malicious Chart.yaml Content And Symlink Can Lead To Code Execuโ€ฆ

Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a Chart.lock file when dependโ€ฆ

๐Ÿ“… Published: July 8, 2025, 9:39 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

9.8

CVSS3.1

CVE-2025-49533 - Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502)

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

๐Ÿ“… Published: July 8, 2025, 9:32 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

6.9

CVSS4.0

CVE-2025-7197 - code-projects Jonnys Liquor delete-row.php sql injection

A vulnerability classified as critical has been found in code-projects Jonnys Liquor 1.0. This affects an unknown part of the file /admin/delete-row.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to theโ€ฆ

๐Ÿ“… Published: July 8, 2025, 9:32 p.m. ๐Ÿ”„ Last Modified: July 13, 2025, 9:08 p.m.
Total resulsts: 344986
Page 4298 of 34,499
ยซ previous page ยป next page
Filters