0.0

CVE-2025-31248 -

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.5, macOS Sonoma 14.7.3. An app may be able to access sensitive user data.

πŸ“… Published: Nov. 21, 2025, 9:22 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:22 p.m.

8.8

CVSS3.1

CVE-2025-11087 - Zegen Core <= 2.0.1 - Cross-Site Request Forgery to Arbitrary File Upload

The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.0.1. This is due to missing nonce validation and missing file type validation in the '/custom-font-code/custom-fonts-uploads.php' file. This makes it possible…

πŸ“… Published: Nov. 21, 2025, 8:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 8:29 p.m.

6.8

CVSS4.0

CVE-2025-13524 -

Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call participant to continue receiving audio input from another user after they close their call window. This issue occurs under certain conditions, which require th…

πŸ“… Published: Nov. 21, 2025, 8:03 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 8:03 p.m.

6.3

CVSS3.1

CVE-2025-36149 - IBM Concert Software clickjacking

IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.

πŸ“… Published: Nov. 21, 2025, 7:38 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:38 p.m.

5.5

CVSS3.1

CVE-2025-48502 -

Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.

πŸ“… Published: Nov. 21, 2025, 7:07 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:19 p.m.

5.5

CVSS4.0

CVE-2025-62609 - MLX has Wild Pointer Dereference in load_gguf()

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This is…

πŸ“… Published: Nov. 21, 2025, 6:57 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:16 p.m.

5.5

CVSS4.0

CVE-2025-62608 - MLX has heap-buffer-overflow in load()

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds read, leading to crash or information disclosure. This issue …

πŸ“… Published: Nov. 21, 2025, 6:56 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:16 p.m.

7.2

CVSS4.0

CVE-2025-62626 -

Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.

πŸ“… Published: Nov. 21, 2025, 6:52 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:16 p.m.

9.1

CVSS3.1

CVE-2025-64767 - hpke-js reuses AEAD nonces

hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can lead to complete loss of Confidential…

πŸ“… Published: Nov. 21, 2025, 6:47 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:16 p.m.

5.3

CVSS3.1

CVE-2025-29934 -

A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.

πŸ“… Published: Nov. 21, 2025, 6:45 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:15 p.m.
Total resulsts: 319157
Page 6 of 31,916
Β« previous page Β» next page
Filters