8.3

CVSS4.0

CVE-2025-27791 - Collabora Online Vulnerable to Arbitrary File Write

Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, there is a path traversal flaw in handling the CheckFileInfo BaseFileName field returned from WOPI servers. This allows for a file to be written anywhereโ€ฆ

๐Ÿ“… Published: April 15, 2025, 7:09 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS4.0

CVE-2025-24358 - gorilla/csrf CSRF vulnerability due to broken Referer validation

gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior to 1.7.2, gorilla/csrf does not validate the Origin header against an allowlist. Its executes its validation of the Referer header for cross-origin requests only when it believes โ€ฆ

๐Ÿ“… Published: April 15, 2025, 6:57 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2023-5616 - gnome-control-center: Remote login misconfiguration in GNOME Control Center

In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.

๐Ÿ“… Published: April 15, 2025, 6:29 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 4:34 p.m.

2.1

CVSS4.0

CVE-2024-42193 - HCL BigFix Web Reports is susceptible to a Man-In-The-Middle (MITM) attack

HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized accesโ€ฆ

๐Ÿ“… Published: April 15, 2025, 6:16 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 7:29 p.m.

5.6

CVSS4.0

CVE-2024-42189 - HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack

HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

๐Ÿ“… Published: April 15, 2025, 6:07 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 7:21 p.m.

4.8

CVSS4.0

CVE-2024-42200 - HCL BigFix Web Reports is potentially susceptible to a Stored Cross-Site Scripting (XSS) attack

HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.

๐Ÿ“… Published: April 15, 2025, 6 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 7:22 p.m.

8.5

CVSS4.0

CVE-2025-3618 - Local Privilege Escalation Vulnerability

A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on the target software.

๐Ÿ“… Published: April 15, 2025, 5:19 p.m. ๐Ÿ”„ Last Modified: July 14, 2025, 7:17 p.m.

8.5

CVSS4.0

CVE-2025-3617 - Local Privilege Escalation in ThinManagerยฎ

A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat actor could inherit eโ€ฆ

๐Ÿ“… Published: April 15, 2025, 5:17 p.m. ๐Ÿ”„ Last Modified: July 14, 2025, 7:16 p.m.

7.3

CVSS3.1

CVE-2025-32780 - BleachBit for Windows Has DLL Untrusted Path Vulnerability

BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerable to a DLL Hijacking vulnerability. By placing a malicious DLL with the name uuid.dll in the folder C:\Users\<username>\AppData\Local\Microsoft\WindowsApps\, an attacker can execโ€ฆ

๐Ÿ“… Published: April 15, 2025, 4:32 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-32779 - labsai/eddi Vulnerable to Path Traversal (Zip Slip) in ZIP Import Function

E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0, an attacker with access to the `/backup/import` API endpoint can write arbitrary files to locations outside the intended extraction directory due to a Zip Slip vulnerability. Altโ€ฆ

๐Ÿ“… Published: April 15, 2025, 4:32 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347821
Page 5742 of 34,783
ยซ previous page ยป next page
Filters