7.7

CVSS4.0

CVE-2025-9178 - Rockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service Vulnerability

A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP communication using crafted payloads. The security issue could result in no CIP communication with 1715 EtherNet/IP Adapter.A restart is required to recover.

πŸ“… Published: Oct. 14, 2025, 12:51 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:51 p.m.

7.7

CVSS4.0

CVE-2025-9177 - Rockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service Vulnerability

A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the web server. This could result in a web server crash however; this does not impact I/O control or communicationΒ . A power cycle is required to recover an…

πŸ“… Published: Oct. 14, 2025, 12:48 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:51 p.m.

7

CVSS4.0

CVE-2025-7330 - Rockwell Automation 1783-NATR Cross-Site Request Forgery Vulnerability

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.

πŸ“… Published: Oct. 14, 2025, 12:43 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:43 p.m.

9.8

CVSS3.1

CVE-2025-10610 - SQLi in SFS Winsure

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure allows Blind SQL Injection.This issue affects Winsure: through Version dated 21.08.2025.

πŸ“… Published: Oct. 14, 2025, 12:43 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 7:36 p.m.

5.3

CVSS4.0

CVE-2025-11498 - CSV Formula Injection Vulnerability

An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attack…

πŸ“… Published: Oct. 14, 2025, 12:42 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 7:36 p.m.

8.5

CVSS4.0

CVE-2025-7329 - Rockwell Automation Comms - 1783-NATR Stored Cross-Site Scripting Vulnerability

A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation require…

πŸ“… Published: Oct. 14, 2025, 12:37 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:40 p.m.

9.9

CVSS4.0

CVE-2025-7328 - Rockwell Automation Comms - 1783-NATR Multiple Broken Authentication Vulnerabilities

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would no longer be able to …

πŸ“… Published: Oct. 14, 2025, 12:35 p.m. πŸ”„ Last Modified: Oct. 14, 2025, 12:40 p.m.

0.0

CVE-2025-11720 -

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vul…

πŸ“… Published: Oct. 14, 2025, 12:27 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:19 p.m.

0.0

CVE-2025-11718 -

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event This vulnerability affects Firefox < 144.

πŸ“… Published: Oct. 14, 2025, 12:27 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:24 p.m.

0.0

CVE-2025-11717 -

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability affects Firefox < 144.

πŸ“… Published: Oct. 14, 2025, 12:27 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:24 p.m.
Total resulsts: 314406
Page 45 of 31,441
Β« previous page Β» next page
Filters