6.9

CVSS4.0

CVE-2025-27090 - Server-Side Request Forgery (SSRF) in sliver teamserver

Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the op…

πŸ“… Published: Feb. 19, 2025, 9:11 p.m. πŸ”„ Last Modified: Feb. 27, 2025, 8:18 p.m.

5.8

CVSS4.0

CVE-2025-25196 - OpenFGA Authorization Bypass

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users on Ope…

πŸ“… Published: Feb. 19, 2025, 8:18 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 2:18 p.m.

7.8

CVSS3.1

CVE-2025-0893 -

Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.

πŸ“… Published: Feb. 19, 2025, 5:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-53974 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

πŸ“… Published: Feb. 19, 2025, 5:31 p.m. πŸ”„ Last Modified: July 12, 2025, 10:15 p.m.

2.3

CVSS4.0

CVE-2025-24806 - Regulation applies separately to Username-based logins to Email-based logins in authelia

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. If users are allowed to sign in via both username and email the regulation system treats these as separate login events. This leads to t…

πŸ“… Published: Feb. 19, 2025, 5:19 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-1006 -

Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. (Chromium security severity: Medium)

πŸ“… Published: Feb. 19, 2025, 4:55 p.m. πŸ”„ Last Modified: April 7, 2025, 7:07 p.m.

8.8

CVSS3.1

CVE-2025-1426 -

Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Feb. 19, 2025, 4:55 p.m. πŸ”„ Last Modified: April 7, 2025, 7:07 p.m.

8.8

CVSS3.1

CVE-2025-0999 -

Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Feb. 19, 2025, 4:55 p.m. πŸ”„ Last Modified: April 7, 2025, 7:07 p.m.

8.5

CVSS4.0

CVE-2025-24965 - .krun_config.json symlink attack creates or overwrites file on the host in crun

crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host. No special permissions are needed, only the ability for the current u…

πŸ“… Published: Feb. 19, 2025, 4:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2024-52541 -

Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

πŸ“… Published: Feb. 19, 2025, 4:46 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 7:22 p.m.
Total resulsts: 349182
Page 6683 of 34,919
Β« previous page Β» next page
Filters