4.6

CVSS3.1

CVE-2025-32964 - ManageWiki vulnerable to permission bypass when disabling extensions requiring certain permissions …

ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting extension, a restricted extension would be automatically disabled even if the user did not hold the ManageWiki-restricted right. This issue has been patched in commit 00bebea. A …

πŸ“… Published: April 22, 2025, 5:15 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:46 p.m.

6.9

CVSS4.0

CVE-2025-32963 - Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS

MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. …

πŸ“… Published: April 22, 2025, 5:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-32950 - io.jmix.localfs:jmix-localfs has a Path Traversal in Local File Storage

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, attackers could manipulate the FileRef parameter to access files on the system where the Jmix application is deployed, provided the application server ha…

πŸ“… Published: April 22, 2025, 5:14 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 4:04 p.m.

4.3

CVSS3.1

CVE-2025-32788 - OctoPrint Authenticated Reverse Proxy Page Authentication Bypass

OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker to bypass the login redirect and directly access the rendered HTML of certain frontend pages. The primary risk lies in potential fut…

πŸ“… Published: April 22, 2025, 5:14 p.m. πŸ”„ Last Modified: June 27, 2025, 3:40 p.m.

9.3

CVSS4.0

CVE-2025-34028 - Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Travers…

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue af…

πŸ“… Published: April 22, 2025, 4:32 p.m. πŸ”„ Last Modified: Nov. 29, 2025, 2:06 a.m.

4.1

CVSS3.1

CVE-2025-27907 - IBM WebSphere Application Server server-side request forgery

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

πŸ“… Published: April 22, 2025, 4:20 p.m. πŸ”„ Last Modified: Sept. 1, 2025, 12:38 a.m.

7.6

CVSS3.1

CVE-2025-23251 -

NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.

πŸ“… Published: April 22, 2025, 3:42 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.6

CVSS3.1

CVE-2025-23250 -

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tampering.

πŸ“… Published: April 22, 2025, 3:35 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.6

CVSS3.1

CVE-2025-23249 -

NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.

πŸ“… Published: April 22, 2025, 3:30 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.2

CVSS3.1

CVE-2025-3767 - SQL Injection in Centreon BAM boolean KPI listing

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection. This page is only accessible to authenticated users with high privileges. This issue affects Centreon BAM: from 24.10 before 24.1…

πŸ“… Published: April 22, 2025, 3:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346624
Page 5439 of 34,663
Β« previous page Β» next page
Filters