8.1

CVSS3.1

CVE-2025-5268 - Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11

Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firef…

📅 Published: May 27, 2025, 12:29 p.m. 🔄 Last Modified: April 20, 2026, 5:15 p.m.

5.4

CVSS3.1

CVE-2025-5267 - Clickjacking vulnerability could have led to leaking saved payment card details

A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

📅 Published: May 27, 2025, 12:29 p.m. 🔄 Last Modified: April 20, 2026, 5:15 p.m.

4.3

CVSS3.1

CVE-2025-5266 - Script element events leaked cross-origin resource status

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

📅 Published: May 27, 2025, 12:29 p.m. 🔄 Last Modified: April 20, 2026, 5:15 p.m.

4.8

CVSS3.1

CVE-2025-5265 - Potential local code execution in “Copy as cURL” command

Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.*. Th…

📅 Published: May 27, 2025, 12:29 p.m. 🔄 Last Modified: April 20, 2026, 5:15 p.m.

4.8

CVSS3.1

CVE-2025-5264 - Potential local code execution in “Copy as cURL” command

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunder…

📅 Published: May 27, 2025, 12:29 p.m. 🔄 Last Modified: April 20, 2026, 8:45 p.m.

4.3

CVSS3.1

CVE-2025-5263 - Error handling for script execution was incorrectly isolated from web content

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

📅 Published: May 27, 2025, 12:29 p.m. 🔄 Last Modified: April 20, 2026, 8:45 p.m.

8.8

CVSS3.1

CVE-2025-5117 - Property 1.0.5 - 1.0.6 - Missing Authorization to Authenticated (Author+) Privilege Escalation via …

The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata in versions 1.0.5 to 1.0.6. This makes it possible for authenticated attackers, with Author‐level access and above, to elevate their privil…

📅 Published: May 27, 2025, 11:14 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-4412 - TCC Bypass via Dylib Loading in Viscosity.app

On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC (Transparency, Consent, and Control) identity. The acquired resource access is limited without entitlements such as acce…

📅 Published: May 27, 2025, 10:09 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-41653 - Weidmueller: Denial-of-Service Vulnerability in the web server functionality of Industrial Ethernet…

An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted HTTP request with a malicious header, potentially causing the server to crash or become unresponsive.

📅 Published: May 27, 2025, 8:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-41652 - Weidmueller: Authentication Bypass Vulnerability in Industrial Ethernet Switches

The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated remote attacker could exploit this weakness by performing brute-force attacks to guess valid credentials or by using MD5 collision techniques to forge authentication hashes, potent…

📅 Published: May 27, 2025, 8:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348147
Page 5141 of 34,815
« previous page » next page
Filters