8.4

CVSS4.0

CVE-2025-61856 -

A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

πŸ“… Published: Oct. 10, 2025, 10:19 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 10:19 a.m.

6.5

CVSS3.1

CVE-2025-52632 - HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability

A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

πŸ“… Published: Oct. 10, 2025, 10:06 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 10:06 a.m.

5.7

CVSS3.1

CVE-2025-37727 - Elasticsearch Insertion of sensitive information in log file

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

πŸ“… Published: Oct. 10, 2025, 9:56 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 4:34 p.m.

3.7

CVSS3.1

CVE-2025-52630 - HCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerability

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

πŸ“… Published: Oct. 10, 2025, 9:55 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:55 a.m.

8.2

CVSS3.1

CVE-2025-25017 - Kibana Stored Cross-Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

πŸ“… Published: Oct. 10, 2025, 9:53 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:53 a.m.

7.3

CVSS3.1

CVE-2025-30001 - Apache StreamPark: Authenticated users can trigger remote command execution

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.

πŸ“… Published: Oct. 10, 2025, 9:52 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 6:58 p.m.

8.7

CVSS3.1

CVE-2025-25018 - Kibana Stored Cross-Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

πŸ“… Published: Oct. 10, 2025, 9:50 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:51 a.m.

3.7

CVSS3.1

CVE-2025-52634 - HCL AION is susceptible to Spring Boot Actuator Endpoints Exposed

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AIONΒ This issue affects HCL AION: 2.0.

πŸ“… Published: Oct. 10, 2025, 9:40 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:40 a.m.

8.2

CVSS3.1

CVE-2025-52650 - HCL AION is susceptible to Inline script execution allowed in CSP vulnerability

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

πŸ“… Published: Oct. 10, 2025, 9:30 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:30 a.m.

4.8

CVSS4.0

CVE-2025-41089 - Reflected Cross-Site Scripting (XSS) in CMS

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock'…

πŸ“… Published: Oct. 10, 2025, 9:19 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 9:19 a.m.
Total resulsts: 313670
Page 8 of 31,367
Β« previous page Β» next page
Filters