7.1

CVSS4.0

CVE-2025-20068 -

Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via …

📅 Published: March 10, 2026, 10:49 p.m. 🔄 Last Modified: March 13, 2026, 9:54 a.m.

8.7

CVSS4.0

CVE-2025-20064 -

Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially occur via local…

📅 Published: March 10, 2026, 10:49 p.m. 🔄 Last Modified: March 13, 2026, 9:54 a.m.

7.1

CVSS4.0

CVE-2025-20028 -

Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occ…

📅 Published: March 10, 2026, 10:49 p.m. 🔄 Last Modified: March 13, 2026, 9:54 a.m.

7.1

CVSS4.0

CVE-2025-20027 -

Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local a…

📅 Published: March 10, 2026, 10:49 p.m. 🔄 Last Modified: March 13, 2026, 9:54 a.m.

5.6

CVSS4.0

CVE-2025-20005 -

Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access whe…

📅 Published: March 10, 2026, 10:49 p.m. 🔄 Last Modified: March 13, 2026, 9:54 a.m.

5.9

CVSS4.0

CVE-2025-20096 -

Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access when attac…

📅 Published: March 10, 2026, 10:31 p.m. 🔄 Last Modified: March 13, 2026, 9:54 a.m.

6.9

CVSS4.0

CVE-2026-31838 - Istio HTTP debug endpoints on port 15014 to enforce namespace-based authorization, preventing cross…

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain multiple values. An attacker could craft requests wi…

📅 Published: March 10, 2026, 9:58 p.m. 🔄 Last Modified: April 15, 2026, 10:45 p.m.

8.7

CVSS4.0

CVE-2026-31837 - Istio JWKS resolver to prevent private key material from being exposed when JWKS fetch fails.

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerabili…

📅 Published: March 10, 2026, 9:57 p.m. 🔄 Last Modified: April 16, 2026, 3:15 a.m.

7.2

CVSS3.1

CVE-2026-31834 - Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks

Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated backoffice users with permission to manage users, may be able to elevate their privileges due to insufficient authoriz…

📅 Published: March 10, 2026, 9:53 p.m. 🔄 Last Modified: April 16, 2026, 9:30 a.m.

6.7

CVSS3.1

CVE-2026-31833 - Umbraco has Stored XSS in UFM Rendering Pipeline via Permissive DOMPurify Attribute Filtering

Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTML into property type descriptions. Due to an overly permissive attributeNameCheck configuration (/.+/) in the UFM DOMPurify instance, event handler at…

📅 Published: March 10, 2026, 9:51 p.m. 🔄 Last Modified: April 16, 2026, 9:30 a.m.
Total resulsts: 349182
Page 1198 of 34,919
« previous page » next page
Filters