7.8

CVSS3.1

CVE-2022-50052 - ASoC: Intel: avs: Fix potential buffer overflow by snprintf()

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Fix potential buffer overflow by snprintf() snprintf() returns the would-be-filled size when the string overflows the given buffer size, hence using this value may result in a buffer overflow (although it's unre…

πŸ“… Published: June 18, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 6:41 p.m.

5.5

CVSS3.1

CVE-2025-38032 - mr: consolidate the ipmr_can_free_table() checks.

In the Linux kernel, the following vulnerability has been resolved: mr: consolidate the ipmr_can_free_table() checks. Guoyu Yin reported a splat in the ipmr netns cleanup path: WARNING: CPU: 2 PID: 14564 at net/ipv4/ipmr.c:440 ipmr_free_table net/ipv4/ipmr.c:440 [inline] WARNING: CPU: 2 PID: 145…

πŸ“… Published: June 18, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:09 p.m.

5.3

CVSS4.0

CVE-2025-49149 - Dify has XSS vulnerability

Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers can use website vulnerabilities to inject malicious script code into web pages. This may result in a cross-site scripting (XSS) attack when a user brow…

πŸ“… Published: June 17, 2025, 10:34 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 10:13 p.m.

9.8

CVSS3.1

CVE-2025-49825 - Teleport allows remote authentication bypass

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.

πŸ“… Published: June 17, 2025, 9:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-49593 - Portainer HTTP Headers May Leak to Malicious Container Registries

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious …

πŸ“… Published: June 17, 2025, 9:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-49385 -

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

πŸ“… Published: June 17, 2025, 8:40 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 7:39 p.m.

7.8

CVSS3.1

CVE-2025-49384 -

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

πŸ“… Published: June 17, 2025, 8:40 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 7:39 p.m.

1.7

CVSS4.0

CVE-2025-49824 - conda-smithy Insecure Encryption Vulnerable to Oracle Padding Attack

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_encrypt_binstar_token implementation in the conda-smithy package has been identified as vulnerable to an Oracle Padding Atta…

πŸ“… Published: June 17, 2025, 8:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS4.0

CVE-2025-49843 - conda-smithy Has Incorrect Default File Permissions

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.47.1, the travis_headers function in the conda-smithy repository creates files with permissions exceeding 0o600, allowing read and write acce…

πŸ“… Published: June 17, 2025, 8:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-48443 -

Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the administrator installs Trend M…

πŸ“… Published: June 17, 2025, 8:34 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 2:33 a.m.
Total resulsts: 349182
Page 4999 of 34,919
Β« previous page Β» next page
Filters