6.5

CVSS3.1

CVE-2025-22602 - Stored DOM-based XSS (without CSP) via video placeholders in Discourse

Discourse is an open source platform for community discussion. In affected versions an attacker can execute arbitrary JavaScript on users' browsers by posting a malicious video placeholder html element. This issue only affects sites with CSP disabled. This problem has been patched in the latest ver…

πŸ“… Published: Feb. 4, 2025, 8:51 p.m. πŸ”„ Last Modified: Sept. 26, 2025, 1:01 p.m.

8.2

CVSS3.1

CVE-2025-23023 - Anonymous cache poisoning via request headers in Discourse

Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a request with the right request headers to poison the anonymous cache (for example, the cache may have a response with missing preloaded data). This issue only affects anonymous vis…

πŸ“… Published: Feb. 4, 2025, 8:48 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 4:29 p.m.

5

CVSS3.1

CVE-2024-45657 - IBM Security Verify Access incorrect privilege assignment

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.

πŸ“… Published: Feb. 4, 2025, 8:40 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 8:04 p.m.

6.5

CVSS3.1

CVE-2024-35138 - IBM Security Verify Access cross-site request forgery

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

πŸ“… Published: Feb. 4, 2025, 8:38 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 9:13 p.m.

5.9

CVSS3.1

CVE-2024-43187 - IBM Security Verify Access information disclosure

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

πŸ“… Published: Feb. 4, 2025, 8:37 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 8:04 p.m.

2.7

CVSS3.1

CVE-2024-45658 - IBM Security Verify Access information disclosure

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

πŸ“… Published: Feb. 4, 2025, 8:37 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 5:12 p.m.

6.1

CVSS3.1

CVE-2024-40700 - IBM Security Verify Access cross-site scripting

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu…

πŸ“… Published: Feb. 4, 2025, 8:36 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 8:01 p.m.

7.3

CVSS3.1

CVE-2025-0509 - Signing Checks Bypass

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.

πŸ“… Published: Feb. 4, 2025, 8:01 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 2:35 p.m.

6

CVSS4.0

CVE-2025-0630 - Western Telematic Inc NPS Series, DSM Series, CPM Series External Control of File Name or Path

Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged access to files on the device's filesystem.

πŸ“… Published: Feb. 4, 2025, 7:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-24963 - Browser mode serves arbitrary files in vitest

Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by `browser.api.host: true`, an attacker can send a request to that handler from remote to ge…

πŸ“… Published: Feb. 4, 2025, 7:36 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 2:44 p.m.
Total resulsts: 349182
Page 6849 of 34,919
Β« previous page Β» next page
Filters