6.5

CVSS3.1

CVE-2025-3599 - Symantec Endpoint Protection Elevation of Privilege

Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.

πŸ“… Published: April 30, 2025, 4:49 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 5:32 p.m.

4.3

CVSS3.1

CVE-2025-3859 - Firefox Focus elide URL allows address bar spoofing

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus 138.

πŸ“… Published: April 30, 2025, 4:30 p.m. πŸ”„ Last Modified: April 20, 2026, 5:15 p.m.

4.8

CVSS4.0

CVE-2025-32376 - Discourse DM limits aren’t always properly enforced

Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site in it. This issue has been patched in stable ver…

πŸ“… Published: April 30, 2025, 2:55 p.m. πŸ”„ Last Modified: May 16, 2025, 4:28 p.m.

8.6

CVSS3.1

CVE-2025-46342 - Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using namespace selector(s) in their match statements are mistakenly not applied during admission review request processing due to a missing error pr…

πŸ“… Published: April 30, 2025, 2:55 p.m. πŸ”„ Last Modified: May 16, 2025, 4:42 p.m.

8.8

CVSS3.1

CVE-2025-27134 - Privilege escalation in Joplin server via user patch endpoint

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin server, allowing non-admin users to exploit the API endpoint `PATCH /api/users/:id` t…

πŸ“… Published: April 30, 2025, 2:55 p.m. πŸ”„ Last Modified: May 16, 2025, 4:32 p.m.

7.5

CVSS3.1

CVE-2025-27409 - Joplin Server Vulnerable to Path Traversal

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, path traversal is possible in Joplin Server if static file path starts with `css/pluginAssets` or `js/pluginAssets`. The `findLocalFile` functi…

πŸ“… Published: April 30, 2025, 2:55 p.m. πŸ”„ Last Modified: May 16, 2025, 4:29 p.m.

9.1

CVSS3.1

CVE-2025-32973 - org.xwiki.platform:xwiki-platform-component-wiki provides no warning when granting XWiki.ComponentC…

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, when a user with programming rights edits a document in XWiki that was last edited by a user without programming rights and contai…

πŸ“… Published: April 30, 2025, 2:55 p.m. πŸ”„ Last Modified: May 13, 2025, 2:58 p.m.

9.1

CVSS3.1

CVE-2025-32974 - org.xwiki.platform:xwiki-platform-security-requiredrights-default required rights analysis doesn't …

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAreas with default content type. When editing a page, XWiki warns since version 15.9 when there is content on the page lik…

πŸ“… Published: April 30, 2025, 2:55 p.m. πŸ”„ Last Modified: May 13, 2025, 2:55 p.m.

2.7

CVSS3.1

CVE-2025-32972 - The lesscss script service allows cache clearing without programming right

XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the script API of the LESS compiler in XWiki is incorrectly checking for rights when calling the cache cleaning API, making …

πŸ“… Published: April 30, 2025, 2:54 p.m. πŸ”„ Last Modified: May 13, 2025, 3:05 p.m.

3.8

CVSS3.1

CVE-2025-32971 - XWiki Solr script service doesn't take dropped programming right into account

XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Solr script service that is accessible in XWiki's sc…

πŸ“… Published: April 30, 2025, 2:54 p.m. πŸ”„ Last Modified: May 13, 2025, 3:06 p.m.
Total resulsts: 349182
Page 5625 of 34,919
Β« previous page Β» next page
Filters