8.8

CVSS3.1

CVE-2025-6381 - BeeTeam368 Extensions <= 2.3.4 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File โ€ฆ

The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outsideโ€ฆ

๐Ÿ“… Published: June 28, 2025, 3:21 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 8:30 p.m.

8.8

CVSS3.1

CVE-2025-6379 - BeeTeam368 Extensions Pro <= 2.3.4 - Authenticated (Subscriber+) Directory Traversal to Arbitrary Fโ€ฆ

The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_live_fn() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of tโ€ฆ

๐Ÿ“… Published: June 28, 2025, 3:21 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 5:15 p.m.

6.4

CVSS3.1

CVE-2024-52900 - IBM Cognos Analytics cross-site scripting

IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials diโ€ฆ

๐Ÿ“… Published: June 28, 2025, 12:59 a.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:37 a.m.

5.4

CVSS3.1

CVE-2025-36027 - IBM Datacap clickjacking

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks againsโ€ฆ

๐Ÿ“… Published: June 28, 2025, 12:51 a.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:39 a.m.

4.3

CVSS3.1

CVE-2025-36026 - IBM Datacap information disclosure

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link anโ€ฆ

๐Ÿ“… Published: June 28, 2025, 12:49 a.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:38 a.m.

5.4

CVSS3.1

CVE-2024-39730 - IBM Datacap clickjacking

IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks โ€ฆ

๐Ÿ“… Published: June 28, 2025, 12:36 a.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:37 a.m.

5

CVSS3.1

CVE-2025-53392 -

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed throughโ€ฆ

๐Ÿ“… Published: June 28, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 15, 2025, 8:09 p.m.

5.5

CVSS3.1

CVE-2025-38086 - net: ch9200: fix uninitialised access during mii_nway_restart

In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nway_restart In mii_nway_restart() the code attempts to call mii->mdio_read which is ch9200_mdio_read(). ch9200_mdio_read() utilises a local buffer called "buff", which is initialiโ€ฆ

๐Ÿ“… Published: June 28, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 17, 2025, 4:36 p.m.

4.7

CVSS3.1

CVE-2025-38085 - mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that may have previously been shared across processes, potentially turning it into a normal page table used in another proceโ€ฆ

๐Ÿ“… Published: June 28, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 9:21 p.m.

5.5

CVSS3.1

CVE-2025-38084 - mm/hugetlb: unshare page tables during VMA split, not before

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, not before Currently, __split_vma() triggers hugetlb page table unsharing through vm_ops->may_split(). This happens before the VMA lock and rmap locks are taken - which is too eaโ€ฆ

๐Ÿ“… Published: June 28, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 18, 2025, 9:20 p.m.
Total resulsts: 349182
Page 4849 of 34,919
ยซ previous page ยป next page
Filters