7.8

CVSS3.1

CVE-2025-21735 - NFC: nci: Add bounds checking in nci_hci_create_pipe()

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corruption in the caller, nci_hci_connect_gate().

📅 Published: Feb. 27, 2025, midnight 🔄 Last Modified: Nov. 3, 2025, 8:17 p.m.

7.1

CVSS3.1

CVE-2025-21815 - mm/compaction: fix UBSAN shift-out-of-bounds warning

In the Linux kernel, the following vulnerability has been resolved: mm/compaction: fix UBSAN shift-out-of-bounds warning syzkaller reported a UBSAN shift-out-of-bounds warning of (1UL << order) in isolate_freepages_block(). The bogus compound_order can be any value because it is union with flags…

📅 Published: Feb. 27, 2025, midnight 🔄 Last Modified: Oct. 28, 2025, 2:53 a.m.

0.0

CVE-2025-1728 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

📅 Published: Feb. 26, 2025, 9:16 p.m. 🔄 Last Modified: Feb. 26, 2025, 10:15 p.m.

4.3

CVSS3.1

CVE-2025-1726 - [#BUG-000172669 ArcGIS Monitor has a security vulnerability]

There is a SQL injection issue in Esri ArcGIS Monitor versions 2023.0 through 2024.x on Windows and Linux that allows a remote, authenticated attacker with low privileges to improperly read limited database schema information by passing crafted queries. While it is possible to enumerate some intern…

📅 Published: Feb. 26, 2025, 7:28 p.m. 🔄 Last Modified: Feb. 27, 2025, 8:48 p.m.

5.8

CVSS3.1

CVE-2025-0941 - MET ONE 3400+ Potential Credential Exposure

MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain text within the system. This data is not available to unauthenticated users.

📅 Published: Feb. 26, 2025, 4:28 p.m. 🔄 Last Modified: Feb. 26, 2025, 5:15 p.m.

6

CVSS3.1

CVE-2025-20119 - Cisco Application Policy Infrastructure Controller Authenticated Local Denial of Service Vulnerabil…

A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is d…

📅 Published: Feb. 26, 2025, 4:23 p.m. 🔄 Last Modified: July 31, 2025, 5:40 p.m.

4.4

CVSS3.1

CVE-2025-20118 - Cisco Application Policy Infrastructure Controller Authenticated Command Injection Due to Sensitive…

A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is d…

📅 Published: Feb. 26, 2025, 4:23 p.m. 🔄 Last Modified: July 31, 2025, 5:38 p.m.

5.1

CVSS3.1

CVE-2025-20161 - Cisco NX-OS Software Command Injection Vulnerability

A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating syste…

📅 Published: Feb. 26, 2025, 4:12 p.m. 🔄 Last Modified: Feb. 27, 2025, 3:18 p.m.

5.1

CVSS3.1

CVE-2025-20117 - Cisco Application Policy Infrastructure Controller Authenticated Command Injection Vulnerability

A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root&nbsp;on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is…

📅 Published: Feb. 26, 2025, 4:11 p.m. 🔄 Last Modified: July 31, 2025, 5:37 p.m.

4.8

CVSS3.1

CVE-2025-20116 - Cisco Application Policy Infrastructure Controller Stored Cross-Site Scripting Vulnerability

A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper input validation in the we…

📅 Published: Feb. 26, 2025, 4:11 p.m. 🔄 Last Modified: July 31, 2025, 5:34 p.m.
Total resulsts: 342363
Page 5866 of 34,237
« previous page » next page
Filters