7.1

CVSS4.0

CVE-2025-64442 - HumHub is vulnerable to XSS through its Meta Search component

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.

πŸ“… Published: Nov. 7, 2025, 8:28 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.4

CVSS3.1

CVE-2025-12896 -

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked storage device.

πŸ“… Published: Nov. 7, 2025, 8:24 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.4

CVSS3.1

CVE-2025-12902 -

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked Storage Device or create a Denial of Service.

πŸ“… Published: Nov. 7, 2025, 8:18 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.4

CVSS4.0

CVE-2025-64439 - LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 2.1.2 and below, the JsonPlusSerializer (used as the default serialization protocol for all checkpointing) contains a Remote Code Execution (RCE) vulne…

πŸ“… Published: Nov. 7, 2025, 8:15 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-36006 - IBM Db2 denial of service

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial due to the improper release of resources after use.

πŸ“… Published: Nov. 7, 2025, 7:04 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-36008 - IBM Db2 denial of service

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper allocation of resources.

πŸ“… Published: Nov. 7, 2025, 6:57 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.6

CVSS3.1

CVE-2025-36131 - IBM Db2 information disclosure

IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus command exposes user credentials to the terminal which could be obtained by a third party with physical access to the system.

πŸ“… Published: Nov. 7, 2025, 6:53 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

5.1

CVSS3.1

CVE-2025-36136 - IBM denial of service

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause a denial of service due to the database monitor script incorrectly detecting that the instance is still starting under specific conditions.

πŸ“… Published: Nov. 7, 2025, 6:45 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.2

CVSS3.1

CVE-2025-36185 - IBM Db2 denial of service

IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.

πŸ“… Published: Nov. 7, 2025, 6:40 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-12890 - Bluetooth: peripheral: Invalid handling of malformed connection request

Improper handling of malformed Connection Request with the interval set to be 1 (which supposed to be illegal) and the chM 0x7CFFFFFFFF triggers a crash. The peripheral will not be connectable after it.

πŸ“… Published: Nov. 7, 2025, 6:40 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318197
Page 83 of 31,820
Β« previous page Β» next page
Filters