9.8

CVSS3.1

CVE-2025-1012 - Use-after-free during concurrent delazification

A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

πŸ“… Published: Feb. 4, 2025, 1:58 p.m. πŸ”„ Last Modified: April 22, 2026, 4:30 a.m.

9.8

CVSS3.1

CVE-2025-1011 - A bug in WebAssembly code generation could result in a crash

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

πŸ“… Published: Feb. 4, 2025, 1:58 p.m. πŸ”„ Last Modified: April 20, 2026, 6:30 p.m.

7.3

CVSS3.1

CVE-2025-1018 - Fullscreen notification is not displayed when fullscreen is re-requested

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability was fixed in Firefox 135 and Thunderbird 135.

πŸ“… Published: Feb. 4, 2025, 1:58 p.m. πŸ”„ Last Modified: April 21, 2026, 10:30 p.m.

9.8

CVSS3.1

CVE-2025-1010 - Use-after-free in Custom Highlight

An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

πŸ“… Published: Feb. 4, 2025, 1:58 p.m. πŸ”„ Last Modified: April 22, 2026, 7:15 a.m.

9.8

CVSS3.1

CVE-2025-1009 - Use-after-free in XSLT

An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

πŸ“… Published: Feb. 4, 2025, 1:58 p.m. πŸ”„ Last Modified: April 20, 2026, 6:45 p.m.

4.8

CVSS4.0

CVE-2024-11623 - Stored XSS in authentik

Authentik project is vulnerable to Stored XSS attacks throughΒ uploading crafted SVG files that are used as application icons.Β  This action could only be performed by an authenticated admin user. The issue was fixed inΒ 2024.10.4 release.

πŸ“… Published: Feb. 4, 2025, 1:34 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 6:41 p.m.

6.4

CVSS3.1

CVE-2024-13699 - Qi Addons For Elementor <= 1.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜cursor’ parameter in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…

πŸ“… Published: Feb. 4, 2025, 12:22 p.m. πŸ”„ Last Modified: April 8, 2026, 5:15 p.m.

5.3

CVSS3.1

CVE-2024-27137 - Apache Cassandra: unrestricted deserialization of JMX authentication credentials

In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use the…

πŸ“… Published: Feb. 4, 2025, 10:19 a.m. πŸ”„ Last Modified: July 14, 2025, 12:43 p.m.

5.4

CVSS3.1

CVE-2025-24860 - Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing a…

Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can update their own permissions via data control …

πŸ“… Published: Feb. 4, 2025, 10:17 a.m. πŸ”„ Last Modified: June 9, 2025, 7:43 p.m.

9.8

CVSS3.1

CVE-2025-0890 -

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials …

πŸ“… Published: Feb. 4, 2025, 10:06 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:02 p.m.
Total resulsts: 349182
Page 6855 of 34,919
Β« previous page Β» next page
Filters