8.8

CVSS3.1

CVE-2025-11087 - Zegen Core <= 2.0.1 - Cross-Site Request Forgery to Arbitrary File Upload

The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.0.1. This is due to missing nonce validation and missing file type validation in the '/custom-font-code/custom-fonts-uploads.php' file. This makes it possible…

πŸ“… Published: Nov. 21, 2025, 8:29 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 8:29 p.m.

6.8

CVSS4.0

CVE-2025-13524 -

Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call participant to continue receiving audio input from another user after they close their call window. This issue occurs under certain conditions, which require th…

πŸ“… Published: Nov. 21, 2025, 8:03 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 8:03 p.m.

6.3

CVSS3.1

CVE-2025-36149 - IBM Concert Software clickjacking

IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.

πŸ“… Published: Nov. 21, 2025, 7:38 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:38 p.m.

5.5

CVSS3.1

CVE-2025-48502 -

Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.

πŸ“… Published: Nov. 21, 2025, 7:07 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:19 p.m.

5.5

CVSS4.0

CVE-2025-62609 - MLX has Wild Pointer Dereference in load_gguf()

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This is…

πŸ“… Published: Nov. 21, 2025, 6:57 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:16 p.m.

5.5

CVSS4.0

CVE-2025-62608 - MLX has heap-buffer-overflow in load()

MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflow in mlx::core::load() when parsing malicious NumPy .npy files. Attacker-controlled file causes 13-byte out-of-bounds read, leading to crash or information disclosure. This issue …

πŸ“… Published: Nov. 21, 2025, 6:56 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:16 p.m.

7.2

CVSS4.0

CVE-2025-62626 -

Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.

πŸ“… Published: Nov. 21, 2025, 6:52 p.m. πŸ”„ Last Modified: Nov. 23, 2025, 4:49 p.m.

9.1

CVSS3.1

CVE-2025-64767 - hpke-js reuses AEAD nonces

hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API has a race condition which allows for the same AEAD nonce to be re-used for multiple Seal() calls. This can lead to complete loss of Confidential…

πŸ“… Published: Nov. 21, 2025, 6:47 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:16 p.m.

5.3

CVSS3.1

CVE-2025-29934 -

A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.

πŸ“… Published: Nov. 21, 2025, 6:45 p.m. πŸ”„ Last Modified: Nov. 23, 2025, 5:30 p.m.

5.1

CVSS4.0

CVE-2025-64169 - Wazuh NULL pointer dereference in fim_alert line 666

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to before 4.12.0, fim_alert() implementation does not check whether oldsum->md5 is NULL or not before dereferencing it. A compromised agent can cause a crash of analysisd by sending a sp…

πŸ“… Published: Nov. 21, 2025, 6:39 p.m. πŸ”„ Last Modified: Nov. 21, 2025, 7:16 p.m.
Total resulsts: 319156
Page 6 of 31,916
Β« previous page Β» next page
Filters