7.8

CVSS3.1

CVE-2023-35685 -

In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

📅 Published: Jan. 8, 2025, 5:35 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:15 p.m.

6.5

CVSS3.1

CVE-2024-6350 - EmberZNet malformed MAC layer packet leads to denial of service

A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error condition automatically.

📅 Published: Jan. 8, 2025, 5:12 p.m. 🔄 Last Modified: Jan. 8, 2025, 6:15 p.m.

4.8

CVSS4.0

CVE-2024-13187 - Kingsoft WPS Office TCC code injection

A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component TCC Handler. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit h…

📅 Published: Jan. 8, 2025, 4:31 p.m. 🔄 Last Modified: July 12, 2025, 10:31 p.m.

5.4

CVSS3.1

CVE-2025-20168 - Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-suppl…

📅 Published: Jan. 8, 2025, 4:19 p.m. 🔄 Last Modified: July 23, 2025, 4:11 p.m.

5.4

CVSS3.1

CVE-2025-20167 - Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-suppl…

📅 Published: Jan. 8, 2025, 4:19 p.m. 🔄 Last Modified: July 23, 2025, 4:11 p.m.

5.4

CVSS3.1

CVE-2025-20166 - Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-suppl…

📅 Published: Jan. 8, 2025, 4:19 p.m. 🔄 Last Modified: July 23, 2025, 3:47 p.m.

4.8

CVSS3.1

CVE-2025-20126 - Cisco ThousandEyes Endpoint Agent Certificate Validation Vulnerability

A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. This vulnerability exists because the affected software does not properly validate certif…

📅 Published: Jan. 8, 2025, 4:09 p.m. 🔄 Last Modified: July 22, 2025, 3:33 p.m.

4.8

CVSS3.1

CVE-2025-20123 - Cisco Crosswork Network Controller Stored Cross-Site Scripting Vulnerability

Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users of the interface of an affected system. These vulnerabilities exist because the web-based…

📅 Published: Jan. 8, 2025, 4:09 p.m. 🔄 Last Modified: July 23, 2025, 3:39 p.m.

9.8

CVSS3.1

CVE-2025-22137 - Arbitrary File Overwrite via HTTP POST in Pingvin Share

Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, including sensitive system files, via HTTP POST requests. The issu…

📅 Published: Jan. 8, 2025, 4:08 p.m. 🔄 Last Modified: Jan. 8, 2025, 7:28 p.m.

8.6

CVSS4.0

CVE-2025-22136 - Tabby has a TCC Bypass via Misconfigured Node Fuses

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection vectors even though the …

📅 Published: Jan. 8, 2025, 4:02 p.m. 🔄 Last Modified: Jan. 8, 2025, 7:25 p.m.
Total resulsts: 344009
Page 6706 of 34,401
« previous page » next page
Filters