6.2

CVSS3.1

CVE-2025-8090 - Vulnerability in the QNX Neutrino Kernel impacts the QNX Software Development Platform and QNX OS f…

Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel.

📅 Published: Jan. 13, 2026, 4:36 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2025-25249 -

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to ex…

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Feb. 26, 2026, 3:04 p.m.

9.3

CVSS3.1

CVE-2025-47855 -

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.4

CVSS3.1

CVE-2025-67685 -

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy internal requests limited to plaintext en…

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:38 p.m.

5.7

CVSS3.1

CVE-2025-58693 -

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:34 p.m.

6.8

CVSS3.1

CVE-2025-59922 -

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenti…

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:38 p.m.

9.4

CVSS3.1

CVE-2025-64155 -

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unaut…

📅 Published: Jan. 13, 2026, 4:32 p.m. 🔄 Last Modified: Feb. 26, 2026, 3:04 p.m.

9.1

CVSS3.1

CVE-2025-25176 - GPU DDK - GPU Register value contents leaked from secure workloads to non-secure world

Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

📅 Published: Jan. 13, 2026, 4:27 p.m. 🔄 Last Modified: Jan. 30, 2026, 6:37 p.m.

6.6

CVSS3.1

CVE-2025-46684 -

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering.

📅 Published: Jan. 13, 2026, 4:19 p.m. 🔄 Last Modified: Feb. 13, 2026, 9:02 p.m.

4.8

CVSS4.0

CVE-2026-0404 - Insufficient input validation in NETGEAR Orbi routers

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

📅 Published: Jan. 13, 2026, 4:01 p.m. 🔄 Last Modified: April 18, 2026, 6:45 a.m.
Total resulsts: 346802
Page 1932 of 34,681
« previous page » next page
Filters