4.6

CVSS4.0

CVE-2025-1368 - MicroWord eScan Antivirus mwav.conf ReadConfiguration buffer overflow

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects the function ReadConfiguration of the file /opt/MicroWorld/etc/mwav.conf. The manipulation of the argument BasePath leads to buffer overflow. Local access is requiโ€ฆ

๐Ÿ“… Published: Feb. 17, 2025, 1 a.m. ๐Ÿ”„ Last Modified: June 27, 2025, 5:45 p.m.

4.8

CVSS4.0

CVE-2025-1367 - MicroWord eScan Antivirus USB Password sprintf buffer overflow

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. This affects the function sprintf of the component USB Password Handler. The manipulation leads to buffer overflow. An attack has to be approached locally. The vendor was contacted early abouโ€ฆ

๐Ÿ“… Published: Feb. 17, 2025, 12:31 a.m. ๐Ÿ”„ Last Modified: June 27, 2025, 5:46 p.m.

4.8

CVSS4.0

CVE-2025-1366 - MicroWord eScan Antivirus VirusPopUp strcpy stack-based overflow

A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this issue is the function strcpy of the component VirusPopUp. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been discloโ€ฆ

๐Ÿ“… Published: Feb. 17, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:44 p.m.

6.8

CVSS3.1

CVE-2025-26465 - Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For โ€ฆ

๐Ÿ“… Published: Feb. 17, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 29, 2026, 6:20 p.m.

4.3

CVSS3.1

CVE-2024-25066 -

RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.

๐Ÿ“… Published: Feb. 17, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-1391 - Keycloak-services: improper authorization in keycloak organization mapper allows unauthorized organโ€ฆ

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organizationโ€™s domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on โ€ฆ

๐Ÿ“… Published: Feb. 17, 2025, midnight ๐Ÿ”„ Last Modified: May 6, 2026, 4:48 p.m.

7.8

CVSS3.1

CVE-2025-0591 - Out-of-bounds Read vulnerability in CX-Programmer

Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability.

๐Ÿ“… Published: Feb. 16, 2025, 11:58 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-1365 - GNU elfutils eu-readelf readelf.c process_symtab buffer overflow

A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach this attack. The exploiโ€ฆ

๐Ÿ“… Published: Feb. 16, 2025, 11:31 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 8:07 p.m.

4.8

CVSS4.0

CVE-2025-1364 - MicroWord eScan Antivirus USB Protection Service passPrompt stack-based overflow

A vulnerability has been found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this vulnerability is the function passPrompt of the component USB Protection Service. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on thโ€ฆ

๐Ÿ“… Published: Feb. 16, 2025, 11 p.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 3:05 p.m.

4.9

CVSS3.1

CVE-2025-26779 - WordPress Keep Backup Daily plugin <= 2.1.0 - Arbitrary File Download vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fahad Mahmood Keep Backup Daily keep-backup-daily allows Path Traversal.This issue affects Keep Backup Daily: from n/a through <= 2.1.0.

๐Ÿ“… Published: Feb. 16, 2025, 10:17 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:25 p.m.
Total resulsts: 348552
Page 6653 of 34,856
ยซ previous page ยป next page
Filters