7.3

CVSS3.1

CVE-2025-30167 - Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerabiliโ€ฆ

Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create confโ€ฆ

๐Ÿ“… Published: June 3, 2025, 4:42 p.m. ๐Ÿ”„ Last Modified: Jan. 23, 2026, 5:16 p.m.

5.3

CVSS4.0

CVE-2025-5510 - quequnlong shiyi-blog optimize server-side request forgery

A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknown code of the file /app/sys/article/optimize. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has beenโ€ฆ

๐Ÿ“… Published: June 3, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: June 9, 2025, 3:13 p.m.

5.3

CVSS4.0

CVE-2025-5509 - quequnlong shiyi-blog upload path traversal

A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload. The manipulation of the argument file/source leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosedโ€ฆ

๐Ÿ“… Published: June 3, 2025, 4 p.m. ๐Ÿ”„ Last Modified: June 9, 2025, 3:14 p.m.

4.8

CVSS4.0

CVE-2025-5508 - TOTOLINK A3002RU IP Port Filtering Page cross site scripting

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IP Port Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack may be launched remoโ€ฆ

๐Ÿ“… Published: June 3, 2025, 4 p.m. ๐Ÿ”„ Last Modified: June 6, 2025, 3:14 p.m.

4.8

CVSS4.0

CVE-2025-5507 - TOTOLINK A3002RU MAC Filtering Page cross site scripting

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component MAC Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack can be launchedโ€ฆ

๐Ÿ“… Published: June 3, 2025, 3:31 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 8:40 p.m.

6.5

CVSS3.1

CVE-2025-25020 - IBM QRadar Suite Software and IBM Cloud Pak for Security improper input validation

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input.

๐Ÿ“… Published: June 3, 2025, 3:19 p.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, noon

4

CVSS3.1

CVE-2025-1334 - IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosure

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.

๐Ÿ“… Published: June 3, 2025, 3:18 p.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:59 a.m.

7.2

CVSS3.1

CVE-2025-25021 - IBM QRadar Suite Software and IBM Cloud Pak for Security code injection

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code.

๐Ÿ“… Published: June 3, 2025, 3:17 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

9.6

CVSS3.1

CVE-2025-25022 - IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosure

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.

๐Ÿ“… Published: June 3, 2025, 3:16 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

4.8

CVSS3.1

CVE-2025-25019 - IBM QRadar Suite Software and IBM Cloud Pak for Security session fixation

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.

๐Ÿ“… Published: June 3, 2025, 3:14 p.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, noon
Total resulsts: 346621
Page 4931 of 34,663
ยซ previous page ยป next page
Filters