8.8

CVSS3.1

CVE-2025-37736 - Elastic Cloud Enterprise Improper Authorization

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs that are affected by this issue is: post:/platform/configuration/security/service-accounts delete:/platform/configurat…

πŸ“… Published: Nov. 7, 2025, 10:08 p.m. πŸ”„ Last Modified: Nov. 11, 2025, 4:55 a.m.

9.2

CVSS4.0

CVE-2020-36870 - Ruijie Gateway EG & NBR Models v11.1(6)B9P1 - 11.9(4)B12P1 RCE

Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management system that can be abused via front-end functionality. Attackers can exploit front-end code when features such as guest authentication, local server au…

πŸ“… Published: Nov. 7, 2025, 9:52 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 7:43 p.m.

5.6

CVSS4.0

CVE-2025-12418 - Potential Denial of Service in Supported Versions of Revenera InstallShield

Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user writeable configuration directory and induce a Denial of Servic…

πŸ“… Published: Nov. 7, 2025, 9:27 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

0

CVSS3.1

CVE-2025-64481 - Open redirect endpoint in Datasette

Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability. Hits to the path //example.com/foo/bar/ (the trailing slash is required) will redirect the user to…

πŸ“… Published: Nov. 7, 2025, 8:35 p.m. πŸ”„ Last Modified: Nov. 13, 2025, 2:23 p.m.

4.8

CVSS4.0

CVE-2025-12875 - mruby array.c ary_fill_exec out-of-bounds write

A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing manipulation of the argument start/length can lead to out-of-bounds write. The attack needs to be launched locally. The exploit has been ma…

πŸ“… Published: Nov. 7, 2025, 8:32 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.1

CVSS4.0

CVE-2025-64442 - HumHub is vulnerable to XSS through its Meta Search component

HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search feature which allows malicious input to be executed in search previews. This issue is fixed in version 1.17.4.

πŸ“… Published: Nov. 7, 2025, 8:28 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.4

CVSS3.1

CVE-2025-12896 -

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked storage device.

πŸ“… Published: Nov. 7, 2025, 8:24 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

4.4

CVSS3.1

CVE-2025-12902 -

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked Storage Device or create a Denial of Service.

πŸ“… Published: Nov. 7, 2025, 8:18 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

7.4

CVSS4.0

CVE-2025-64439 - LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 2.1.2 and below, the JsonPlusSerializer (used as the default serialization protocol for all checkpointing) contains a Remote Code Execution (RCE) vulne…

πŸ“… Published: Nov. 7, 2025, 8:15 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-36006 - IBM Db2 denial of service

IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial due to the improper release of resources after use.

πŸ“… Published: Nov. 7, 2025, 7:04 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318212
Page 84 of 31,822
Β« previous page Β» next page
Filters