7.5

CVSS3.1

CVE-2025-31674 - Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

πŸ“… Published: March 31, 2025, 9:34 p.m. πŸ”„ Last Modified: May 1, 2025, 2:35 p.m.

4.6

CVSS3.1

CVE-2025-31673 - Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002

Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

πŸ“… Published: March 31, 2025, 9:34 p.m. πŸ”„ Last Modified: June 2, 2025, 4:25 p.m.

6.1

CVSS3.1

CVE-2025-3057 - Drupal core - Critical - Cross site scripting - SA-CORE-2025-001

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

πŸ“… Published: March 31, 2025, 9:33 p.m. πŸ”„ Last Modified: April 15, 2025, 2:31 p.m.

4.8

CVSS4.0

CVE-2025-3017 - TA-Lib ta_regtest test_minmax.c setInputBuffer out-of-bounds write

A vulnerability, which was classified as critical, has been found in TA-Lib up to 0.6.4. This issue affects the function setInputBuffer of the file src/tools/ta_regtest/ta_test_func/test_minmax.c of the component ta_regtest. The manipulation leads to out-of-bounds write. It is possible to launch th…

πŸ“… Published: March 31, 2025, 9:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-3016 - Open Asset Import Library Assimp MDL File MDLMaterialLoader.cpp ParseTextureColorData resource cons…

A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument m…

πŸ“… Published: March 31, 2025, 9 p.m. πŸ”„ Last Modified: April 17, 2025, 12:19 p.m.

5.9

CVSS3.1

CVE-2024-24456 -

An E-RAB Release Command packet containing a malformed NAS PDUΒ will cause the Athonet MME to immediately crash, potentially due to aΒ buffer overflow.

πŸ“… Published: March 31, 2025, 8:33 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-3015 - Open Asset Import Library Assimp ASE File ASELoader.cpp BuildUniqueRepresentation out-of-bounds

A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to…

πŸ“… Published: March 31, 2025, 8:31 p.m. πŸ”„ Last Modified: April 17, 2025, 12:51 p.m.

4.8

CVSS4.0

CVE-2025-3010 - Khronos Group glslang Intermediate.cpp isConversionAllowed null pointer dereference

A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this issue is the function glslang::TIntermediate::isConversionAllowed of the file glslang/MachineIndependent/Intermediate.cpp. The manipulation leads to null pointer dereference. The a…

πŸ“… Published: March 31, 2025, 8 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-31124 - Zitadel allows User Enumeration by loginname attribute normalization

Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password prompt even if the user doesn't exist and report "U…

πŸ“… Published: March 31, 2025, 7:38 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:15 p.m.

8.7

CVSS3.1

CVE-2025-31123 - Zitadel Expired JWT Keys Usable for Authorization Grants

Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of the JWT key when used for Authorization Grants. This allows an attacker with an expired key to obt…

πŸ“… Published: March 31, 2025, 7:31 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:13 p.m.
Total resulsts: 349182
Page 6117 of 34,919
Β« previous page Β» next page
Filters