6.5

CVSS3.1

CVE-2025-2877 - Event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activatio…

A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: March 20, 2026, 6:16 p.m.

7.8

CVSS3.1

CVE-2025-27833 - Ghostscript: Buffer overflow with long TTF font name

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 4:44 p.m.

7.5

CVSS3.1

CVE-2025-30118 -

An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials for all devices and does not implement proper multi-device authentication, allowing attackers to deny the owner access by occupying the only availabl…

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

9.4

CVSS4.0

CVE-2025-30091 -

In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into config.php, and InstallCommand is available afte…

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

7.5

CVSS3.1

CVE-2025-25371 -

NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 3:17 p.m.

9.8

CVSS3.1

CVE-2024-55030 -

A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 3:13 p.m.

5.4

CVSS3.1

CVE-2025-27809 -

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: July 17, 2025, 3:57 p.m.

9.8

CVSS3.1

CVE-2025-27831 - Ghostscript: Text buffer overflow with long characters

An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

9.8

CVSS3.1

CVE-2024-42533 -

SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

8.3

CVSS3.1

CVE-2025-2783 - mojo: chromium: chromium Mojo on Windows

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.
Total resulsts: 342254
Page 5536 of 34,226
Β« previous page Β» next page
Filters