6.1

CVSS3.1

CVE-2025-20351 - Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware…

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI. This vulnerability exists because the web…

📅 Published: Oct. 15, 2025, 4:15 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

7.5

CVSS3.1

CVE-2025-20350 - Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware…

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to a buffer overflow…

📅 Published: Oct. 15, 2025, 4:15 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:40 a.m.

4.9

CVSS3.1

CVE-2025-20329 - Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability

A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploit this vulnerability, the attacker must have valid administr…

📅 Published: Oct. 15, 2025, 4:14 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

5.3

CVSS3.1

CVE-2025-58133 - Zoom Rooms Clients - Authentication Bypass

Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access.

📅 Published: Oct. 15, 2025, 4:13 p.m. 🔄 Last Modified: Oct. 21, 2025, 7:33 p.m.

4.1

CVSS3.1

CVE-2025-58132 - Zoom Clients for Windows - Command Injection

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

📅 Published: Oct. 15, 2025, 4:10 p.m. 🔄 Last Modified: Oct. 21, 2025, 7:32 p.m.

3.1

CVSS3.1

CVE-2025-62379 - Open Redirect in reflex-dev/reflex

Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace endpoint automatically assigns the redirect_to query parameter value directly to client-side links without any validation and triggers automatic clicks when the page loads in a Git…

📅 Published: Oct. 15, 2025, 3:57 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:40 a.m.

5.5

CVSS4.0

CVE-2025-59419 - Netty netty-codec-smtp SMTP Command Injection Vulnerability Allowing Email Forgery

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supp…

📅 Published: Oct. 15, 2025, 3:42 p.m. 🔄 Last Modified: Oct. 20, 2025, 1:25 p.m.

7.5

CVSS3.1

CVE-2025-62370 - Alloy Core has a DoS vulnerability on `alloy_dyn_abi::TypedData` hashing

Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered by malformed input to alloy_dyn_abi::TypedData could lead to a denial-of-service (DoS) via eip712_signing_hash(). Software with high availability requirements such as network serv…

📅 Published: Oct. 15, 2025, 3:32 p.m. 🔄 Last Modified: Oct. 21, 2025, 1:09 p.m.

2.9

CVSS3.1

CVE-2025-2529 - IBM Terracotta denial of service

Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way.

📅 Published: Oct. 15, 2025, 3:29 p.m. 🔄 Last Modified: Oct. 16, 2025, 3:28 p.m.

8.7

CVSS4.0

CVE-2025-61990 - TMM vulnerability

When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

📅 Published: Oct. 15, 2025, 3:19 p.m. 🔄 Last Modified: Oct. 21, 2025, 12:12 p.m.
Total resulsts: 314947
Page 54 of 31,495
« previous page » next page
Filters