5.8

CVSS4.0

CVE-2025-22831 - Buffer Overflow in NTFS when parsing the VOLUME_NAME

APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and loss of availability.

๐Ÿ“… Published: Oct. 14, 2025, 2 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 2 p.m.

7.2

CVSS3.1

CVE-2025-47856 -

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requesโ€ฆ

๐Ÿ“… Published: Oct. 14, 2025, 1:42 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 1:57 p.m.

7.7

CVSS4.0

CVE-2025-9178 - Rockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service Vulnerability

A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP communication using crafted payloads. The security issue could result in no CIP communication with 1715 EtherNet/IP Adapter.A restart is required to recover.

๐Ÿ“… Published: Oct. 14, 2025, 12:51 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 12:51 p.m.

7.7

CVSS4.0

CVE-2025-9177 - Rockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service Vulnerability

A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the web server. This could result in a web server crash however; this does not impact I/O control or communicationย . A power cycle is required to recover anโ€ฆ

๐Ÿ“… Published: Oct. 14, 2025, 12:48 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 12:51 p.m.

7

CVSS4.0

CVE-2025-7330 - Rockwell Automation 1783-NATR Cross-Site Request Forgery Vulnerability

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.

๐Ÿ“… Published: Oct. 14, 2025, 12:43 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 12:43 p.m.

9.8

CVSS3.1

CVE-2025-10610 - SQLi in SFS Winsure

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure allows Blind SQL Injection.This issue affects Winsure: through Version dated 21.08.2025.

๐Ÿ“… Published: Oct. 14, 2025, 12:43 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 12:43 p.m.

5.3

CVSS4.0

CVE-2025-11498 - CSV Formula Injection Vulnerability

An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attackโ€ฆ

๐Ÿ“… Published: Oct. 14, 2025, 12:42 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 12:42 p.m.

8.5

CVSS4.0

CVE-2025-7329 - Rockwell Automation Comms - 1783-NATR Stored Cross-Site Scripting Vulnerability

A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requireโ€ฆ

๐Ÿ“… Published: Oct. 14, 2025, 12:37 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 12:40 p.m.

9.9

CVSS4.0

CVE-2025-7328 - Rockwell Automation Comms - 1783-NATR Multiple Broken Authentication Vulnerabilities

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would no longer be able to โ€ฆ

๐Ÿ“… Published: Oct. 14, 2025, 12:35 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 12:40 p.m.

0.0

CVE-2025-11720 -

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulโ€ฆ

๐Ÿ“… Published: Oct. 14, 2025, 12:27 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 12:27 p.m.
Total resulsts: 314408
Page 45 of 31,441
ยซ previous page ยป next page
Filters