5.3

CVSS3.1

CVE-2025-64435 - KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate virt-launcher pod associated with the VMI. This can mislea…

πŸ“… Published: Nov. 7, 2025, 10:57 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 7:01 p.m.

4.7

CVSS3.1

CVE-2025-64434 - KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who compromises a virt-handler instance, could exploit these shared credentials to impersonate virt-api and execute privileg…

πŸ“… Published: Nov. 7, 2025, 10:54 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

8.8

CVSS3.1

CVE-2025-37736 - Elastic Cloud Enterprise Improper Authorization

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs that are affected by this issue is: post:/platform/configuration/security/service-accounts delete:/platform/configurat…

πŸ“… Published: Nov. 7, 2025, 10:08 p.m. πŸ”„ Last Modified: Nov. 11, 2025, 4:55 a.m.

9.2

CVSS4.0

CVE-2020-36870 - Ruijie Gateway EG & NBR Models v11.1(6)B9P1 - 11.9(4)B12P1 RCE

Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management system that can be abused via front-end functionality. Attackers can exploit front-end code when features such as guest authentication, local server au…

πŸ“… Published: Nov. 7, 2025, 9:52 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.6

CVSS4.0

CVE-2025-12418 - Potential Denial of Service in Supported Versions of Revenera InstallShield

Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user writeable configuration directory and induce a Denial of Servic…

πŸ“… Published: Nov. 7, 2025, 9:27 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0

CVSS3.1

CVE-2025-64481 - Open redirect endpoint in Datasette

Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability. Hits to the path //example.com/foo/bar/ (the trailing slash is required) will redirect the user to…

πŸ“… Published: Nov. 7, 2025, 8:35 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.8

CVSS4.0

CVE-2025-12875 - mruby array.c ary_fill_exec out-of-bounds write

A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing manipulation of the argument start/length can lead to out-of-bounds write. The attack needs to be launched locally. The exploit has been ma…

πŸ“… Published: Nov. 7, 2025, 8:32 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.1

CVSS4.0

CVE-2025-64442 - HumHub is vulnerable to XSS through its Meta Search component

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.

πŸ“… Published: Nov. 7, 2025, 8:28 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.4

CVSS3.1

CVE-2025-12896 -

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked storage device.

πŸ“… Published: Nov. 7, 2025, 8:24 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.4

CVSS3.1

CVE-2025-12902 -

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked Storage Device or create a Denial of Service.

πŸ“… Published: Nov. 7, 2025, 8:18 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318104
Page 73 of 31,811
Β« previous page Β» next page
Filters