5.5

CVSS3.1

CVE-2025-38314 - virtio-pci: Fix result size returned for the admin command completion

In the Linux kernel, the following vulnerability has been resolved: virtio-pci: Fix result size returned for the admin command completion The result size returned by virtio_pci_admin_dev_parts_get() is 8 bytes larger than the actual result data size. This occurs because the result_sg_size field o…

📅 Published: July 10, 2025, midnight 🔄 Last Modified: Nov. 18, 2025, 12:55 p.m.

7.1

CVSS3.1

CVE-2025-38330 - firmware: cs_dsp: Fix OOB memory read access in KUnit test (ctl cache)

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix OOB memory read access in KUnit test (ctl cache) KASAN reported out of bounds access - cs_dsp_ctl_cache_init_multiple_offsets(). The code uses mock_coeff_template.length_bytes (4 bytes) for register value al…

📅 Published: July 10, 2025, midnight 🔄 Last Modified: Nov. 18, 2025, 12:53 p.m.

8.8

CVSS3.1

CVE-2025-28244 -

Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover

📅 Published: July 10, 2025, midnight 🔄 Last Modified: July 17, 2025, 12:57 a.m.

8.4

CVSS4.0

CVE-2025-0141 - GlobalProtect App: Privilege Escalation (PE) Vulnerability

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. The GlobalProtect app on iOS, Android, Chrome OS and Gl…

📅 Published: July 9, 2025, 10:58 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-0140 - GlobalProtect App: Non Admin User Can Disable the GlobalProtect App

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The GlobalProtect app on Win…

📅 Published: July 9, 2025, 10:58 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-0139 - Autonomous Digital Experience Manager: Privilege Escalation (PE) Vulnerability

An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privileged user on macOS endpoints to escalate their privileges to root.

📅 Published: July 9, 2025, 10:57 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-6976 - Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortc…

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i…

📅 Published: July 9, 2025, 10:22 p.m. 🔄 Last Modified: April 20, 2026, 10:30 p.m.

6.1

CVSS3.1

CVE-2025-6975 - Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping. This makes it possible for una…

📅 Published: July 9, 2025, 10:22 p.m. 🔄 Last Modified: April 21, 2026, 8 p.m.

7.5

CVSS3.1

CVE-2025-6970 - Events Manager <= 7.0.3 - Unauthenticated SQL Injection via `orderby` Parameter

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex…

📅 Published: July 9, 2025, 10:22 p.m. 🔄 Last Modified: April 22, 2026, 4:15 a.m.

10

CVSS3.1

CVE-2025-53624 - docusaurus-plugin-content-gists Exposes GitHub Personal Access Token

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists versions prior to 4.0.0 are vulnerable to exposing GitHub Personal Access Tokens in production build artifacts when passed through plugin configuration …

📅 Published: July 9, 2025, 9:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4701 of 34,919
« previous page » next page
Filters