6.3

CVSS3.1

CVE-2025-33012 - IBM Db2 improper account lockout

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.

πŸ“… Published: Nov. 7, 2025, 6:38 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.3

CVSS3.1

CVE-2025-2534 - IBM Db2 denial of service

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

πŸ“… Published: Nov. 7, 2025, 6:36 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.4

CVSS3.1

CVE-2025-36135 - IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Cross-Site Scripting

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr…

πŸ“… Published: Nov. 7, 2025, 6:26 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2024-47118 - IBM Db2 is vulnerable to a denial of service as the server may crash under certain conditions with …

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

πŸ“… Published: Nov. 7, 2025, 6:23 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

8.7

CVSS4.0

CVE-2025-64431 - IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering

Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) attacks through its V2Beta API, allowing authenticated users with specific administrator roles within one organization to access and modify data belongin…

πŸ“… Published: Nov. 7, 2025, 6:09 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.9

CVSS4.0

CVE-2025-12829 -

An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to Ion text in such a way that sensitive data in memory could be exposed through UTF-8 escape sequences. To mitigate this issue, users should upgrade to version v1.…

πŸ“… Published: Nov. 7, 2025, 6:04 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.1

CVSS4.0

CVE-2025-12873 - Campcodes School File Management update_user.php sql injection

A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to th…

πŸ“… Published: Nov. 7, 2025, 6:02 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.8

CVSS3.1

CVE-2025-9458 - PRT File Parsing Memory Corruption Vulnerability

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

πŸ“… Published: Nov. 7, 2025, 6:01 p.m. πŸ”„ Last Modified: Nov. 8, 2025, 4:55 a.m.

7.5

CVSS3.1

CVE-2025-64430 - Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 through 8.3.1-alpha.1, there is a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality when trying to upload a Parse.File w…

πŸ“… Published: Nov. 7, 2025, 5:55 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.5

CVSS3.1

CVE-2025-64347 - Apollo Router Improperly Enforces Renamed Access Control Directives

Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and below and 2.8.1-rc.0 allow unauthorized access to protected data through schema elements with access control directives (@authenticated, @requiresScopes,…

πŸ“… Published: Nov. 7, 2025, 5:47 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318115
Page 76 of 31,812
Β« previous page Β» next page
Filters