5.3

CVSS3.1

CVE-2025-20234 - ClamAV UDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerab…

πŸ“… Published: June 18, 2025, 4:20 p.m. πŸ”„ Last Modified: Aug. 11, 2025, 6:24 p.m.

4

CVSS3.1

CVE-2025-1348 - IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.

πŸ“… Published: June 18, 2025, 4:19 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:50 a.m.

4.3

CVSS3.1

CVE-2024-54172 - IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site request forgery

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

πŸ“… Published: June 18, 2025, 4:13 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:46 a.m.

8.8

CVSS3.1

CVE-2025-36049 - IBM webMethods Integration Sever XML external entity injection

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.

πŸ“… Published: June 18, 2025, 4:06 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:50 a.m.

7.2

CVSS3.1

CVE-2025-36048 - IBM webMethods Integration Sever code execution

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges.

πŸ“… Published: June 18, 2025, 4:04 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:48 a.m.

7.5

CVSS3.1

CVE-2025-4821 - Incorrect congestion window growth by invalid ACK ranges

Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating …

πŸ“… Published: June 18, 2025, 3:47 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 10:22 p.m.

5.3

CVSS3.1

CVE-2025-4820 - Incorrect congestion window growth by optimistic ACK

Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating …

πŸ“… Published: June 18, 2025, 3:45 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 10:21 p.m.

5.4

CVSS3.1

CVE-2024-54183 - IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially …

πŸ“… Published: June 18, 2025, 3:08 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:47 a.m.

5

CVSS4.0

CVE-2025-6240 - Profisee Path Traversal Vulnerability

Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authentication to the Profisee system.This issue affects Profisee: from 2020R1 before 2024R2.

πŸ“… Published: June 18, 2025, 2:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-6220 - Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload…

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 3.5.12. This makes it possible for authenticated attackers, with Administrator-level access and a…

πŸ“… Published: June 18, 2025, 11:16 a.m. πŸ”„ Last Modified: April 8, 2026, 4:58 p.m.
Total resulsts: 348208
Page 4861 of 34,821
Β« previous page Β» next page
Filters