5.5

CVSS3.1

CVE-2025-41227 - Denial-of-Service Vulnerability

VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service…

📅 Published: May 20, 2025, 2:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-41226 - Guest Operations Denial-of-Service Vulnerability

VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs wi…

📅 Published: May 20, 2025, 2:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-41225 - VMware vCenter Server authenticated command-execution vulnerability

The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.

📅 Published: May 20, 2025, 2:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-47941 - TYPO3 Has Broken Authentication in Backend MFA

TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor authentication (MFA) dialog presented during backend login can be bypassed due to insufficient enforcement of access restric…

📅 Published: May 20, 2025, 2:07 p.m. 🔄 Last Modified: Sept. 3, 2025, 5:22 p.m.

7.2

CVSS3.1

CVE-2025-47940 - TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer

TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintaine…

📅 Published: May 20, 2025, 2:06 p.m. 🔄 Last Modified: Sept. 3, 2025, 5:24 p.m.

5.4

CVSS3.1

CVE-2025-47939 - TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer

TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of any file type, with the exception of those that are directly executable in a web server context. This lack of restriction …

📅 Published: May 20, 2025, 2 p.m. 🔄 Last Modified: Sept. 3, 2025, 5:25 p.m.

6.9

CVSS4.0

CVE-2025-4980 - Netgear DGND3700 mini_http currentsetting.htm information disclosure

A vulnerability has been found in Netgear DGND3700 1.1.00.15_1.00.15NA and classified as problematic. This vulnerability affects unknown code of the file /currentsetting.htm of the component mini_http. The manipulation leads to information disclosure. The attack can be initiated remotely. The explo…

📅 Published: May 20, 2025, 2 p.m. 🔄 Last Modified: June 12, 2025, 4:21 p.m.

3.8

CVSS3.1

CVE-2025-47938 - TYPO3 Vulnerable to Unverified Password Change for Backend Users

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without requiring the current password. When an admi…

📅 Published: May 20, 2025, 1:49 p.m. 🔄 Last Modified: Sept. 3, 2025, 5:26 p.m.

3.7

CVSS3.1

CVE-2025-47937 - TYPO3 Vulnerable to Information Disclosure via DBAL Restriction Handling

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, when performing a database query involving multiple tables through the database abstraction layer (DBAL), frontend…

📅 Published: May 20, 2025, 1:47 p.m. 🔄 Last Modified: Sept. 3, 2025, 5:28 p.m.

3.3

CVSS3.1

CVE-2025-47936 - TYPO3 Vulnerable to Server Side Request Forgery via Webhooks

TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, Webhooks are inherently vulnerable to Cross-Site Request Forgery (CSRF), which can be exploited by adversaries to target internal resources …

📅 Published: May 20, 2025, 1:23 p.m. 🔄 Last Modified: Sept. 3, 2025, 5:30 p.m.
Total resulsts: 349182
Page 5310 of 34,919
« previous page » next page
Filters