3.7

CVSS3.1

CVE-2024-56339 - IBM WebSphere Application Server information disclosure

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7Β could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.

πŸ“… Published: Aug. 7, 2025, 4:03 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 8:02 p.m.

7

CVSS3.1

CVE-2025-47907 - Incorrect results returned from Rows.Scan in database/sql

Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with…

πŸ“… Published: Aug. 7, 2025, 3:25 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 7:11 p.m.

8.7

CVSS4.0

CVE-2025-7054 - Infinite loop triggered by connection ID retirement

Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000 https://datatracker.ietf.org/doc/html/rfc9000#section-5.1 . Once the QUIC …

πŸ“… Published: Aug. 7, 2025, 3:19 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 7:58 p.m.

6.9

CVSS4.0

CVE-2025-8533 - Incorrect Authorization of XPC Service in Fantastical.app

A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting requests from any local process. As a result, any local, unprivileged process could conn…

πŸ“… Published: Aug. 7, 2025, 9:59 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-35970 -

On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information available via SNMP. If the administrator password is not changed from the initial one, a remote attacker with SNMP access can log in to the product with the adminis…

πŸ“… Published: Aug. 7, 2025, 5:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-29866 -

: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035.

πŸ“… Published: Aug. 7, 2025, 5:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-8583 -

Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Aug. 7, 2025, 1:30 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:23 p.m.

4.3

CVSS3.1

CVE-2025-8582 -

Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Aug. 7, 2025, 1:30 a.m. πŸ”„ Last Modified: Nov. 13, 2025, 6:46 p.m.

4.3

CVSS3.1

CVE-2025-8581 -

Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Aug. 7, 2025, 1:30 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:24 p.m.

4.3

CVSS3.1

CVE-2025-8580 -

Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: Aug. 7, 2025, 1:30 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:24 p.m.
Total resulsts: 349182
Page 4375 of 34,919
Β« previous page Β» next page
Filters