4.7

CVSS3.1

CVE-2025-64432 - KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer

KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. It was discovered that the virt-api component fails to correctl…

πŸ“… Published: Nov. 7, 2025, 6:38 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.3

CVSS3.1

CVE-2025-33012 - IBM Db2 improper account lockout

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.

πŸ“… Published: Nov. 7, 2025, 6:38 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.3

CVSS3.1

CVE-2025-2534 - IBM Db2 denial of service

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

πŸ“… Published: Nov. 7, 2025, 6:36 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.4

CVSS3.1

CVE-2025-36135 - IBM Sterling B2B Integrator and IBM Sterling File Gateway are Vulnerable to Cross-Site Scripting

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr…

πŸ“… Published: Nov. 7, 2025, 6:26 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2024-47118 - IBM Db2 is vulnerable to a denial of service as the server may crash under certain conditions with …

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

πŸ“… Published: Nov. 7, 2025, 6:23 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

8.7

CVSS4.0

CVE-2025-64431 - IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering

Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) attacks through its V2Beta API, allowing authenticated users with specific administrator roles within one organization to access and modify data belongin…

πŸ“… Published: Nov. 7, 2025, 6:09 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.9

CVSS4.0

CVE-2025-12829 -

An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to Ion text in such a way that sensitive data in memory could be exposed through UTF-8 escape sequences. To mitigate this issue, users should upgrade to version v1.…

πŸ“… Published: Nov. 7, 2025, 6:04 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.1

CVSS4.0

CVE-2025-12873 - Campcodes School File Management update_user.php sql injection

A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to th…

πŸ“… Published: Nov. 7, 2025, 6:02 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.8

CVSS3.1

CVE-2025-9458 - PRT File Parsing Memory Corruption Vulnerability

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

πŸ“… Published: Nov. 7, 2025, 6:01 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.5

CVSS3.1

CVE-2025-64430 - Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 through 8.3.1-alpha.1, there is a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality when trying to upload a Parse.File w…

πŸ“… Published: Nov. 7, 2025, 5:55 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318147
Page 79 of 31,815
Β« previous page Β» next page
Filters