5.3

CVSS4.0

CVE-2025-62182 - Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file u…

Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.

📅 Published: Jan. 13, 2026, 4:37 p.m. 🔄 Last Modified: Jan. 14, 2026, 4:25 p.m.

6.2

CVSS3.1

CVE-2025-8090 - Vulnerability in the QNX Neutrino Kernel impacts the QNX Software Development Platform and QNX OS f…

Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel.

📅 Published: Jan. 13, 2026, 4:36 p.m. 🔄 Last Modified: Jan. 14, 2026, 4:25 p.m.

7.4

CVSS3.1

CVE-2025-25249 -

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker t…

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 16, 2026, 9:16 a.m.

9.3

CVSS3.1

CVE-2025-47855 -

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 14, 2026, 4:25 p.m.

3.4

CVSS3.1

CVE-2025-67685 -

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy internal requests limited to plaintext en…

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:38 p.m.

5.7

CVSS3.1

CVE-2025-58693 -

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:34 p.m.

6.8

CVSS3.1

CVE-2025-59922 -

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenti…

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:38 p.m.

9.4

CVSS3.1

CVE-2025-64155 -

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unaut…

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:37 p.m.

9.1

CVSS3.1

CVE-2025-25176 - GPU DDK - GPU Register value contents leaked from secure workloads to non-secure world

Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

📅 Published: Jan. 13, 2026, 4:27 p.m. 🔄 Last Modified: Jan. 14, 2026, 4:25 p.m.

4.8

CVSS4.0

CVE-2026-0404 - Insufficient input validation in NETGEAR Orbi routers

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

📅 Published: Jan. 13, 2026, 4:01 p.m. 🔄 Last Modified: Jan. 14, 2026, 4:26 p.m.
Total resulsts: 328117
Page 83 of 32,812
« previous page » next page
Filters