5
CVE-2025-48917 - EU Cookie Compliance (GDPR Compliance) - Moderately critical - Cross Site Scripting - SA-CONTRIB-20β¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie Compliance (GDPR Compliance) allows Cross-Site Scripting (XSS).This issue affects EU Cookie Compliance (GDPR Compliance): from 0.0.0 before 1.26.0.
8.8
CVE-2025-48918 - Simple Klaro - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-071
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.
6.5
CVE-2025-48916 - Bookable Calendar - Less critical - Access bypass - SA-CONTRIB-2025-070
Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.13.
9.4
CVE-2025-6030 - Autoeastern Smart Keyless Entry System Replay Attack
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in theΒ Key Fob Transmitter in Cyclone Matrix TRFΒ Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto.Β Attack confirmed on other KIA Models in Ecuador.
8.4
CVE-2025-36631 - Local Privilege Escalation
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
9.4
CVE-2025-6029 - KIA-branded Aftermarket Generic Smart Keyless Entry System Replay Attack
Use of fixed learning codes, one code to lock the car and the other code to unlock it, theΒ Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is unknown at the time of release.Β CVE Record β¦
8.8
CVE-2025-36633 - Local Privilege Escalation
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.
0.0
CVE-2025-50149 -
Not used
0.0
CVE-2025-50150 -
Not used
0.0
CVE-2025-50148 -
Not used