8.5

CVSS4.0

CVE-2025-10576 - Sound Research SECOMNService Escalation of Privilege

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities.

📅 Published: Oct. 15, 2025, 4:53 p.m. 🔄 Last Modified: Oct. 22, 2025, 3:55 a.m.

2.9

CVSS4.0

CVE-2025-62380 - Mailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails

mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions through 2.0.31 contain an HTML injection vulnerability in plaintext emails generated with the generatePlaintext method when user generated content is supplied. The plaintext generati…

📅 Published: Oct. 15, 2025, 4:52 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:40 a.m.

5.6

CVSS3.1

CVE-2025-54271 - Creative Cloud Desktop | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)

Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check and use of a resource, potentially allowing un…

📅 Published: Oct. 15, 2025, 4:21 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:40 a.m.

5.8

CVSS3.1

CVE-2025-20360 -

Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. This vulnerability is due to a lack of complete error checking when the MIME fields of the HTTP header are pa…

📅 Published: Oct. 15, 2025, 4:19 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

6.5

CVSS3.1

CVE-2025-20359 - Multiple Cisco Products Snort 3 MIME Information Disclosure or Denial of Service Vulnerability

Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. This vulnerability is due to an error in the logic of buffer…

📅 Published: Oct. 15, 2025, 4:17 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

6.1

CVSS3.1

CVE-2025-20351 - Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware…

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI. This vulnerability exists because the web…

📅 Published: Oct. 15, 2025, 4:15 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

7.5

CVSS3.1

CVE-2025-20350 - Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware…

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to a buffer overflow…

📅 Published: Oct. 15, 2025, 4:15 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:40 a.m.

4.9

CVSS3.1

CVE-2025-20329 - Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability

A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploit this vulnerability, the attacker must have valid administr…

📅 Published: Oct. 15, 2025, 4:14 p.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

5.3

CVSS3.1

CVE-2025-58133 - Zoom Rooms Clients - Authentication Bypass

Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access.

📅 Published: Oct. 15, 2025, 4:13 p.m. 🔄 Last Modified: Oct. 21, 2025, 7:33 p.m.

4.1

CVSS3.1

CVE-2025-58132 - Zoom Clients for Windows - Command Injection

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

📅 Published: Oct. 15, 2025, 4:10 p.m. 🔄 Last Modified: Oct. 22, 2025, 3:55 a.m.
Total resulsts: 314962
Page 55 of 31,497
« previous page » next page
Filters