8.3

CVSS4.0

CVE-2025-26508 - Certain HP LaserJet Pro, HP LaserJet Enterprise, HP LaserJet Managed Printers โ€“ Potential Remote Coโ€ฆ

Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.

๐Ÿ“… Published: Feb. 14, 2025, 5:03 p.m. ๐Ÿ”„ Last Modified: Jan. 15, 2026, 2:41 p.m.

6.3

CVSS4.0

CVE-2025-26507 - Certain HP LaserJet Pro, HP LaserJet Enterprise, HP LaserJet Managed Printers โ€“ Potential Remote Coโ€ฆ

Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.

๐Ÿ“… Published: Feb. 14, 2025, 5:01 p.m. ๐Ÿ”„ Last Modified: Jan. 15, 2026, 2:43 p.m.

9.2

CVSS4.0

CVE-2025-26506 - Certain HP LaserJet Pro, HP LaserJet Enterprise, HP LaserJet Managed Printers โ€“ Potential Remote Coโ€ฆ

Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.

๐Ÿ“… Published: Feb. 14, 2025, 4:58 p.m. ๐Ÿ”„ Last Modified: Jan. 15, 2026, 2:41 p.m.

8.7

CVSS4.0

CVE-2025-25295 - Label Studio has a Path Traversal Vulnerability via image Field

Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to 1.0.10 allows unauthorized file access outside the intended directory structure. The flaw exists in the VOC, COCO and YOLO export functionalities. These functions invoke a `downloโ€ฆ

๐Ÿ“… Published: Feb. 14, 2025, 4:50 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2025-25206 - Incorrect input validation could allow an authenticated user to read sensitive information

eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. This could lead to privilege escalation if cookโ€ฆ

๐Ÿ“… Published: Feb. 14, 2025, 4:47 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 6:23 p.m.

6.3

CVSS3.1

CVE-2025-25204 - `gh attestation verify` returns incorrect exit code during verification if no attestations are presโ€ฆ

`gh` is GitHubโ€™s official command line tool. Starting in version 2.49.0 and prior to version 2.67.0, under certain conditions, a bug in GitHub's Artifact Attestation cli tool `gh attestation verify` causes it to return a zero exit status when no attestations are present. This behavior is incorrect:โ€ฆ

๐Ÿ“… Published: Feb. 14, 2025, 4:38 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-8893 -

Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500โ€‘XS allows anyone in physical proximity to the device to fully access the web interface of the inverter via Wiโ€‘Fi.This issue affects GW1500โ€‘XS: 1.1.2.1.

๐Ÿ“… Published: Feb. 14, 2025, 4:33 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2024-3220 - Default mimetype known files writeable on Windows

There is a defect in the CPython standard library module โ€œmimetypesโ€ where on Windows the default list of known file locations are writable meaning other users can create invalid files to cause MemoryError to be raised on Python runtime startup or have file extensions be interpreted as the incorrecโ€ฆ

๐Ÿ“… Published: Feb. 14, 2025, 4:18 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-56463 - IBM QRadar SIEM cross-site scripting

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

๐Ÿ“… Published: Feb. 14, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: Aug. 25, 2025, 10:33 p.m.

6.5

CVSS3.1

CVE-2024-56477 - IBM Power Hardware Management Console directory traversal

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

๐Ÿ“… Published: Feb. 14, 2025, 2:49 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 6:15 p.m.
Total resulsts: 349182
Page 6725 of 34,919
ยซ previous page ยป next page
Filters