5.7

CVSS3.1

CVE-2025-46741 - Improper Privilege Management

A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.

πŸ“… Published: May 12, 2025, 4:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-46740 - Improper Handling of Insufficient Permissions

An authenticated user without user administrative permissions could change the administrator Account Name.

πŸ“… Published: May 12, 2025, 4:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-46739 - Improper Restriction of Excessive Authentication Attempts

An unauthenticated user could discover account credentials via a brute-force attack without rate limiting

πŸ“… Published: May 12, 2025, 4:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2025-46738 - Deserialization of Untrusted Data

An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code.

πŸ“… Published: May 12, 2025, 4:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2025-46737 - Origin Validation Error

SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data gateway service in the application. This gateway service includes an API which is not properly configured to reject requests from unexpected sources.

πŸ“… Published: May 12, 2025, 4:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-47578 - WordPress BNS Twitter Follow Button plugin <= 0.3.8 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow Button bns-twitter-follow-button allows DOM-Based XSS.This issue affects BNS Twitter Follow Button: from n/a through <= 0.3.8.

πŸ“… Published: May 12, 2025, 4:04 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

2.4

CVSS4.0

CVE-2025-47274 - ToolHive stores secrets in the state store with no encryption

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to the ordering of code used to start an MCP server container, versions of ToolHive prior to 0.0.33 inadvertently store secrets in the run config files which are used to restart sto…

πŸ“… Published: May 12, 2025, 2:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2025-46718 - sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others

sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumer…

πŸ“… Published: May 12, 2025, 2:54 p.m. πŸ”„ Last Modified: July 9, 2025, 1:45 a.m.

3.3

CVSS3.1

CVE-2025-46717 - sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders

sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very limited) sudo privileges can determine whether files exists in folders that they otherwise cannot access using `sudo --list <pathname>`. Users with local access to a machine can di…

πŸ“… Published: May 12, 2025, 2:52 p.m. πŸ”„ Last Modified: July 9, 2025, 1:51 a.m.

0.0

CVE-2025-47864 -

Not used

πŸ“… Published: May 12, 2025, 1:58 p.m. πŸ”„ Last Modified: May 13, 2025, 4:16 a.m.
Total resulsts: 349182
Page 5460 of 34,919
Β« previous page Β» next page
Filters