5

CVSS3.1

CVE-2025-5372 - Libssh: incorrect return code handling in ssh_kdf() in libssh

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for successβ€”the function may mistaken…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: April 7, 2026, 8:30 a.m.

10

CVSS3.1

CVE-2025-32975 -

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without v…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: March 24, 2026, 5:44 p.m.

7.1

CVSS3.1

CVE-2025-27828 -

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1.0.5, and 10.2.0.0 through 10.2.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A success…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 9:48 p.m.

4.3

CVSS3.1

CVE-2025-3415 - grafana: Exposure of DingDing alerting integration URL to Viewer level users

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 21, 2025, 3:17 p.m.

6.5

CVSS3.1

CVE-2025-5351 - Libssh: double free vulnerability in libssh key export functions

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional …

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

8.3

CVSS3.1

CVE-2025-6032 - Podman: podman missing tls verification

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: Nov. 29, 2025, 1:16 a.m.

6.1

CVSS3.1

CVE-2024-56916 -

In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field. Once a victim edits …

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 9:48 p.m.

4.2

CVSS3.1

CVE-2025-53073 -

In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publi…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 6, 2025, 10:16 p.m.

7.1

CVSS3.1

CVE-2025-27827 -

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper handling of session data. A successful exploit requires user interaction and could allow an attacker t…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 9:48 p.m.

7.5

CVSS3.1

CVE-2025-32978 -

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to replace system licenses through a web interface intended for license renewal. A…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.
Total resulsts: 343948
Page 4386 of 34,395
Β« previous page Β» next page
Filters