9.8

CVSS3.1

CVE-2025-46724 - Langroid has a Code Injection vulnerability in TableChatAgent

Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `TableChatAgent` uses `pandas eval()`. If fed by untrusted user input, like the case of a public-facing LLM application, it may be vulnerable to code injection. Langroid 0.53.15 saniti…

πŸ“… Published: May 20, 2025, 5:22 p.m. πŸ”„ Last Modified: June 17, 2025, 2:11 p.m.

6.5

CVSS3.1

CVE-2024-45641 - IBM Security ReaQta improper certificate validation

IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.

πŸ“… Published: May 20, 2025, 3:27 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-48018 - Deserialization of Untrusted Data

An authenticated user can modify application state data.

πŸ“… Published: May 20, 2025, 3:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS3.1

CVE-2025-48017 - Improper Limitation of a Pathname to a Restricted Directory

Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading of files

πŸ“… Published: May 20, 2025, 3:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-48016 - Improper Control of Interaction Frequency

OpenFlow discovery protocol can exhaust resources because it is not rate limited

πŸ“… Published: May 20, 2025, 3:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-48015 - Observable Response Discrepancy

Failed login response could be different depending on whether the username was local or central.

πŸ“… Published: May 20, 2025, 3:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-48014 - Improper Restriction of Excessive Authentication Attempts

Password guessing limits could be bypassed when using LDAP authentication.

πŸ“… Published: May 20, 2025, 3:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2023-33861 - IBM Security ReaQta improper certificate validation

IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.

πŸ“… Published: May 20, 2025, 2:51 p.m. πŸ”„ Last Modified: Aug. 16, 2025, 11:42 p.m.

4.3

CVSS3.1

CVE-2025-41228 - VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability

VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation.Β A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.

πŸ“… Published: May 20, 2025, 2:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-41227 - Denial-of-Service Vulnerability

VMware ESXi,Β Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options.Β A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service…

πŸ“… Published: May 20, 2025, 2:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347061
Page 5097 of 34,707
Β« previous page Β» next page
Filters