7.8

CVSS3.1

CVE-2025-26397 - SolarWinds Observability Self-Hosted Deserialization of Untrusted Data Local Privilege Escalation V…

SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires authentication from …

πŸ“… Published: July 24, 2025, 7:57 a.m. πŸ”„ Last Modified: Nov. 12, 2025, 7:17 p.m.

4.9

CVSS3.1

CVE-2025-8009 - Security Ninja – Secure Firewall & Secure Malware Scanner - 5.201 - 5.242 - Authenticated (Administ…

The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get_file_source' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to extra…

πŸ“… Published: July 24, 2025, 7:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-8107 -

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.

πŸ“… Published: July 24, 2025, 7:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7745 - Modbus TCP buffer overread

Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.

πŸ“… Published: July 24, 2025, 7:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-41240 - Mounted Kubernetes Secrets under a predictable path located within the web server document root

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets…

πŸ“… Published: July 24, 2025, 6:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-0765 - Incorrect Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

πŸ“… Published: July 24, 2025, 6:33 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:26 p.m.

4.3

CVSS3.1

CVE-2025-1299 - Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting from 18.2 before 18.2.1 that, under circumstances, could have allowed an unauthorized user to read deployment job logs by sendin…

πŸ“… Published: July 24, 2025, 6:33 a.m. πŸ”„ Last Modified: July 28, 2025, 1:23 p.m.

4.3

CVSS3.1

CVE-2025-4976 - Exposure of Sensitive Information Due to Incompatible Policies in GitLab

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.

πŸ“… Published: July 24, 2025, 6:05 a.m. πŸ”„ Last Modified: July 28, 2025, 2:14 p.m.

4.3

CVSS3.1

CVE-2025-7001 - Insufficient Granularity of Access Control in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should have been unavailable.

πŸ“… Published: July 24, 2025, 6:05 a.m. πŸ”„ Last Modified: July 28, 2025, 2:36 p.m.

9.8

CVSS3.1

CVE-2025-7437 - Ebook Store <= 5.8012 - Unauthenticated Arbitrary File Upload

The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's …

πŸ“… Published: July 24, 2025, 4:24 a.m. πŸ”„ Last Modified: April 22, 2026, 2:45 p.m.
Total resulsts: 349182
Page 4533 of 34,919
Β« previous page Β» next page
Filters