5.5

CVSS3.1

CVE-2025-12748 - Libvirt: denial of service in xml parsing

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too mโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 11, 2025, 8:15 p.m.

8.7

CVSS4.0

CVE-2025-58423 - Advantech DeviceOn/iEdge Path Traversal

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.

๐Ÿ“… Published: Nov. 6, 2025, 10:31 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

8.7

CVSS4.0

CVE-2025-59171 - Advantech DeviceOn/iEdge Path Traversal

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

๐Ÿ“… Published: Nov. 6, 2025, 10:29 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

8.7

CVSS4.0

CVE-2025-62630 - Advantech DeviceOn/iEdge Path Traversal

Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.

๐Ÿ“… Published: Nov. 6, 2025, 10:27 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:54 a.m.

8.1

CVSS3.1

CVE-2025-11458 - chromium-browser: Heap buffer overflow in Sync

Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Nov. 6, 2025, 10:26 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2025, 4:55 a.m.

8.8

CVSS3.1

CVE-2025-11460 - chromium-browser: Use after free in Storage

Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)

๐Ÿ“… Published: Nov. 6, 2025, 10:26 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2025, 4:55 a.m.

8.8

CVSS3.1

CVE-2025-11756 - chromium-browser: Use after free in Safe Browsing

Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Nov. 6, 2025, 10:26 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2025, 4:55 a.m.

8.8

CVSS3.1

CVE-2025-12036 - chromium-browser: Out of bounds memory access in V8

Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Nov. 6, 2025, 10:24 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2025, 4:55 a.m.

5.3

CVSS4.0

CVE-2025-64302 - Advantech DeviceOn/iEdge Cross-site Scripting

Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.

๐Ÿ“… Published: Nov. 6, 2025, 10:24 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

7.1

CVSS4.0

CVE-2025-12636 - Ubia Ubox

The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of settings.

๐Ÿ“… Published: Nov. 6, 2025, 10:15 p.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:54 a.m.
Total resulsts: 317916
Page 65 of 31,792
ยซ previous page ยป next page
Filters