6.5

CVSS3.1

CVE-2025-12890 - Bluetooth: peripheral: Invalid handling of malformed connection request

Improper handling of malformed Connection Request with the interval set to be 1 (which supposed to be illegal) and the chM 0x7CFFFFFFFF triggers a crash. The peripheral will not be connectable after it.

πŸ“… Published: Nov. 7, 2025, 6:40 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.4

CVSS3.1

CVE-2025-36186 - IBM Db2 privilege escalation

IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations could allow a local user to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.

πŸ“… Published: Nov. 7, 2025, 6:40 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.7

CVSS3.1

CVE-2025-64432 - KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer

KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. It was discovered that the virt-api component fails to correctl…

πŸ“… Published: Nov. 7, 2025, 6:38 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 9:33 a.m.

6.3

CVSS3.1

CVE-2025-33012 - IBM Db2 improper account lockout

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.

πŸ“… Published: Nov. 7, 2025, 6:38 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.3

CVSS3.1

CVE-2025-2534 - IBM Db2 denial of service

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

πŸ“… Published: Nov. 7, 2025, 6:36 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.4

CVSS3.1

CVE-2025-36135 - IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Cross-Site Scripting

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr…

πŸ“… Published: Nov. 7, 2025, 6:26 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2024-47118 - IBM Db2 is vulnerable to a denial of service as the server may crash under certain conditions with …

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

πŸ“… Published: Nov. 7, 2025, 6:23 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

8.7

CVSS4.0

CVE-2025-64431 - IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering

Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) attacks through its V2Beta API, allowing authenticated users with specific administrator roles within one organization to access and modify data belongin…

πŸ“… Published: Nov. 7, 2025, 6:09 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.9

CVSS4.0

CVE-2025-12829 -

An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to Ion text in such a way that sensitive data in memory could be exposed through UTF-8 escape sequences. To mitigate this issue, users should upgrade to version v1.…

πŸ“… Published: Nov. 7, 2025, 6:04 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.1

CVSS4.0

CVE-2025-12873 - Campcodes School File Management update_user.php sql injection

A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to th…

πŸ“… Published: Nov. 7, 2025, 6:02 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318108
Page 75 of 31,811
Β« previous page Β» next page
Filters