4.6

CVSS3.1

CVE-2025-29766 - Tuleap has missing CSRF protections on artifact submission & edition from the tracker view

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up coโ€ฆ

๐Ÿ“… Published: March 31, 2025, 3:38 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 10:09 p.m.

4.6

CVSS4.0

CVE-2025-27149 - Zulip exports can leak private data

Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks private data. The collection of user-agent types identifying specific integrations or HTTP libraries (E.g., ZulipGitlabWeโ€ฆ

๐Ÿ“… Published: March 31, 2025, 3:33 p.m. ๐Ÿ”„ Last Modified: Sept. 27, 2025, 12:15 a.m.

4.8

CVSS4.0

CVE-2025-3001 - PyTorch torch.lstm_cell memory corruption

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: March 31, 2025, 3:31 p.m. ๐Ÿ”„ Last Modified: May 29, 2025, 3:53 p.m.

6.9

CVSS4.0

CVE-2025-3048 - Path Traversal in AWS SAM CLI allows file copy to local cache

After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks, the content of those symlinks are copied to the cache of the local workspace as regular files or directories. As a result, a user who does not have access to those symlinks outsidโ€ฆ

๐Ÿ“… Published: March 31, 2025, 3:21 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 8:15 p.m.

6.9

CVSS4.0

CVE-2025-3047 - Path Traversal in AWS SAM CLI allows file copy to build container

When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlinks are included in the build files, the container environment allows a user to access privileged files on the host by leveraging the elevated permissions granted to the tool. A useโ€ฆ

๐Ÿ“… Published: March 31, 2025, 3:21 p.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 8:15 p.m.

4.3

CVSS3.1

CVE-2025-27095 - JumpServer has a Kubernetes Token Leak Vulnerability

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged account can access the Kubernetes session feature and manipulate the kubeconfig file to redirect API requests to an external server controlโ€ฆ

๐Ÿ“… Published: March 31, 2025, 3:08 p.m. ๐Ÿ”„ Last Modified: Nov. 12, 2025, 3:50 p.m.

4.8

CVSS4.0

CVE-2025-3000 - PyTorch torch.jit.script memory corruption

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: March 31, 2025, 3 p.m. ๐Ÿ”„ Last Modified: May 29, 2025, 3:53 p.m.

4.5

CVSS3.1

CVE-2023-33302 -

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an authenticated attacker with regular webmaiโ€ฆ

๐Ÿ“… Published: March 31, 2025, 2:58 p.m. ๐Ÿ”„ Last Modified: July 23, 2025, 3:53 p.m.

4.8

CVSS4.0

CVE-2025-2999 - PyTorch torch.nn.utils.rnn.unpack_sequence memory corruption

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: March 31, 2025, 2:31 p.m. ๐Ÿ”„ Last Modified: May 29, 2025, 3:53 p.m.

8.5

CVSS4.0

CVE-2024-12021 - Stored Cross-Site Scripting

Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interfaces. The impact of exploitation may result in the compromise of local accounts managed by the Coverity platform as well as other standard impacts resulting from cross-site scriptโ€ฆ

๐Ÿ“… Published: March 31, 2025, 2 p.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:26 p.m.
Total resulsts: 343850
Page 5588 of 34,385
ยซ previous page ยป next page
Filters