2.9

CVSS4.0

CVE-2025-49590 - CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability

CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which …

πŸ“… Published: June 18, 2025, 10:14 p.m. πŸ”„ Last Modified: Aug. 11, 2025, 6:18 p.m.

8.8

CVSS3.1

CVE-2025-6192 -

Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: June 18, 2025, 6:16 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.8

CVSS3.1

CVE-2025-6191 -

Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: June 18, 2025, 6:16 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

9.8

CVSS3.1

CVE-2025-20260 - ClamAV PDF Scanning Buffer Overflow Vulnerability

A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. This vulnerability exists because memory buffers are allocated…

πŸ“… Published: June 18, 2025, 5:08 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.6

CVSS3.1

CVE-2025-20271 - Cisco Meraki MX and Z Series AnyConnect VPN with Client Certificate Authentication Denial of Servic…

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. This vulnerability is due…

πŸ“… Published: June 18, 2025, 4:38 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

5.5

CVSS3.1

CVE-2025-1349 - IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti…

πŸ“… Published: June 18, 2025, 4:20 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:50 a.m.

5.3

CVSS3.1

CVE-2025-20234 - ClamAV UDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerab…

πŸ“… Published: June 18, 2025, 4:20 p.m. πŸ”„ Last Modified: Aug. 11, 2025, 6:24 p.m.

4

CVSS3.1

CVE-2025-1348 - IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.

πŸ“… Published: June 18, 2025, 4:19 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:50 a.m.

4.3

CVSS3.1

CVE-2024-54172 - IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site request forgery

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

πŸ“… Published: June 18, 2025, 4:13 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:46 a.m.

8.8

CVSS3.1

CVE-2025-36049 - IBM webMethods Integration Sever XML external entity injection

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.

πŸ“… Published: June 18, 2025, 4:06 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:50 a.m.
Total resulsts: 343850
Page 4425 of 34,385
Β« previous page Β» next page
Filters