7.5

CVSS3.1

CVE-2025-25032 - IBM Cognos Analytics denial of service

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.

๐Ÿ“… Published: June 11, 2025, 5:26 p.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:55 a.m.

5.5

CVSS3.1

CVE-2025-0913 - Inconsistent handling of O_CREATE|O_EXCL on Unix and Windows in os in syscall

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile woulโ€ฆ

๐Ÿ“… Published: June 11, 2025, 5:17 p.m. ๐Ÿ”„ Last Modified: Aug. 8, 2025, 2:53 p.m.

7

CVSS3.1

CVE-2025-40915 - Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens

Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function.

๐Ÿ“… Published: June 11, 2025, 5:09 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:06 p.m.

6.8

CVSS3.1

CVE-2025-4673 - Sensitive headers not cleared on cross-origin redirect in net/http

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

๐Ÿ“… Published: June 11, 2025, 4:42 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:06 p.m.

7.5

CVSS3.1

CVE-2025-22874 - Usage of ExtKeyUsageAny disables policy validation in crypto/x509

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

๐Ÿ“… Published: June 11, 2025, 4:42 p.m. ๐Ÿ”„ Last Modified: June 16, 2025, 8:26 p.m.

7.2

CVSS3.1

CVE-2025-6002 - VirtueMart - Unrestricted File Upload

An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on sโ€ฆ

๐Ÿ“… Published: June 11, 2025, 4:26 p.m. ๐Ÿ”„ Last Modified: June 24, 2025, 9:51 a.m.

8.3

CVSS3.1

CVE-2025-6001 - VirtueMart - Cross Site Request Forgery (CSRF)

A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF request which will allow unrestricted file upload into the VirtueMart media manager.

๐Ÿ“… Published: June 11, 2025, 4:26 p.m. ๐Ÿ”„ Last Modified: June 24, 2025, 9:44 a.m.

2.4

CVSS4.0

CVE-2025-1699 -

An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.

๐Ÿ“… Published: June 11, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:06 p.m.

2.4

CVSS4.0

CVE-2025-1698 -

Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service.

๐Ÿ“… Published: June 11, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:06 p.m.

6.3

CVSS4.0

CVE-2025-26383 -

The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on.

๐Ÿ“… Published: June 11, 2025, 3:36 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:06 p.m.
Total resulsts: 343040
Page 4435 of 34,304
ยซ previous page ยป next page
Filters