7.3

CVSS3.1

CVE-2024-21960 -

Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

πŸ“… Published: May 13, 2025, 4:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-30310 - Dreamweaver Desktop | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)

Dreamweaver Desktop versions 21.4 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o…

πŸ“… Published: May 13, 2025, 4:53 p.m. πŸ”„ Last Modified: May 14, 2025, 2:28 p.m.

7.3

CVSS4.0

CVE-2025-23395 - Local root exploit via `logfile_reopen()` in screen 5.0.0 with setuid-root bit set

Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the…

πŸ“… Published: May 13, 2025, 4:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-46802 - Temporary chown() of users' TTY to mode 0666 allows PTY hijacking in screen

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

πŸ“… Published: May 13, 2025, 4:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-46803 - Screen creates by default world-writable PTYs

The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.

πŸ“… Published: May 13, 2025, 4:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-4658 - Authentication Bypass in OPKSSH

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions prior to 0.5.0 and wo…

πŸ“… Published: May 13, 2025, 4:33 p.m. πŸ”„ Last Modified: May 22, 2025, 6:43 p.m.

9.3

CVSS4.0

CVE-2025-3757 - Authentication Bypass in OpenPubKey

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.

πŸ“… Published: May 13, 2025, 4:33 p.m. πŸ”„ Last Modified: May 23, 2025, 6:56 p.m.

1.8

CVSS4.0

CVE-2025-47278 - Flask uses fallback key instead of current signing key

Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configuration was handled resulted in the last fallback key being used for signing, rather than the current signing key. Signing is provided by the `itsdangerous` library. A list of keys c…

πŸ“… Published: May 13, 2025, 3:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-4428 - Remote Code Execution

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

πŸ“… Published: May 13, 2025, 3:46 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

5.3

CVSS3.1

CVE-2025-4427 - Authentication Bypass

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

πŸ“… Published: May 13, 2025, 3:45 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.
Total resulsts: 346103
Page 5131 of 34,611
Β« previous page Β» next page
Filters