8.1

CVSS3.1

CVE-2025-3030 - Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9

Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox…

πŸ“… Published: April 1, 2025, 12:29 p.m. πŸ”„ Last Modified: April 20, 2026, 6:30 p.m.

7.3

CVSS3.1

CVE-2025-3029 - URL Bar Spoofing via non-BMP Unicode characters

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability was fixed in Firefox 137, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.

πŸ“… Published: April 1, 2025, 12:28 p.m. πŸ”„ Last Modified: April 22, 2026, 2 a.m.

6.5

CVSS3.1

CVE-2025-3028 - Use-after-free triggered by XSLTProcessor

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunderbird 137, and Thunderbird 128.9.

πŸ“… Published: April 1, 2025, 12:28 p.m. πŸ”„ Last Modified: April 20, 2026, 6:30 p.m.

7.8

CVSS3.1

CVE-2025-1659 - DWFX File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: April 1, 2025, 12:28 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:29 p.m.

7.8

CVSS3.1

CVE-2025-1658 - DWFX File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: April 1, 2025, 12:27 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:29 p.m.

8.1

CVSS3.1

CVE-2025-3085 - MongoDB Server running on Linux may allow unexpected connections where intermediate certificates ar…

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to imprope…

πŸ“… Published: April 1, 2025, 12:05 p.m. πŸ”„ Last Modified: Sept. 24, 2025, 3:35 p.m.

6.5

CVSS3.1

CVE-2025-30177 - Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering

Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow c…

πŸ“… Published: April 1, 2025, 11:56 a.m. πŸ”„ Last Modified: April 15, 2025, 1 p.m.

6.5

CVSS3.1

CVE-2025-3084 - MongoDB Server may crash due to improper validation of explain command

When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0 prior to 6.0.20, MongoDB Server v7.0 prior to 7.0.16 and MongoDB Server …

πŸ“… Published: April 1, 2025, 11:14 a.m. πŸ”„ Last Modified: Sept. 24, 2025, 3:37 p.m.

7.5

CVSS3.1

CVE-2025-3083 - Malformed MongoDB wire protocol messages may cause mongos to crash

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31, Β MongoDB v6.0 versions prior toΒ 6.0.20 and MongoDB v7.0 versions prior to 7.0.…

πŸ“… Published: April 1, 2025, 11:12 a.m. πŸ”„ Last Modified: Sept. 22, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2025-2237 - WP RealEstate <= 1.6.26 - Unauthenticated Privilege Escalation via 'process_register'

The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an …

πŸ“… Published: April 1, 2025, 11:12 a.m. πŸ”„ Last Modified: April 20, 2026, 11:30 p.m.
Total resulsts: 348624
Page 6024 of 34,863
Β« previous page Β» next page
Filters