4.8

CVSS3.1

CVE-2025-3129 - Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-028

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.

πŸ“… Published: April 2, 2025, 9:10 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:32 p.m.

9.3

CVSS4.0

CVE-2025-31477 - Improper Scope Validation in the open Endpoint of tauri-plugin-shell

The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open on Linux). This was …

πŸ“… Published: April 2, 2025, 9:10 p.m. πŸ”„ Last Modified: April 29, 2025, 1:30 p.m.

8.2

CVSS3.1

CVE-2025-31479 - canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output

canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-version-action step fails, the exception output may include the GITHUB_TOKEN. If the full token is included in the exceptio…

πŸ“… Published: April 2, 2025, 9:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

1

CVSS4.0

CVE-2025-27608 - Self Cross-Site Scripting in Arduino IDE

Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified within the Arduino-IDE prior to version v2.3.5. The vulnerability occurs in the Additional Board Manager URLs field, which can be found in the Pref…

πŸ“… Published: April 2, 2025, 9:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-2704 -

OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase

πŸ“… Published: April 2, 2025, 9 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 11:15 a.m.

5.3

CVSS4.0

CVE-2025-3118 - SourceCodester Online Tutor Portal view_course.php sql injection

A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit h…

πŸ“… Published: April 2, 2025, 9 p.m. πŸ”„ Last Modified: April 10, 2025, 2:26 p.m.

4.6

CVSS3.1

CVE-2025-31286 -

An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.

πŸ“… Published: April 2, 2025, 4:39 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:32 p.m.

4.6

CVSS3.1

CVE-2025-31285 -

A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the …

πŸ“… Published: April 2, 2025, 4:39 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

4.6

CVSS3.1

CVE-2025-31284 -

A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the bac…

πŸ“… Published: April 2, 2025, 4:39 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

4.6

CVSS3.1

CVE-2025-31283 -

A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the…

πŸ“… Published: April 2, 2025, 4:39 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.
Total resulsts: 346551
Page 5784 of 34,656
Β« previous page Β» next page
Filters