Количество 26 124
Количество 26 124
CVE-2025-47162
Microsoft Office Remote Code Execution Vulnerability
CVE-2025-47161
Microsoft Defender for Endpoint Elevation of Privilege Vulnerability
CVE-2025-47160
Windows Shortcut Files Security Feature Bypass Vulnerability
CVE-2025-47159
Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability
CVE-2025-47158
Azure DevOps Server Elevation of Privilege Vulnerability
CVE-2025-46836
net-tools Stack-based Buffer Overflow vulnerability
CVE-2025-46835
GitHub: CVE-2025-46835 Git File Overwrite Vulnerability
CVE-2025-46819
Redis is vulnerable to DoS via specially crafted LUA scripts
CVE-2025-46818
Redis: Authenticated users can execute LUA scripts as a different user
CVE-2025-46817
Lua library commands may lead to integer overflow and potential RCE
CVE-2025-4674
Unexpected command execution in untrusted VCS repositories in cmd/go
CVE-2025-4673
Sensitive headers not cleared on cross-origin redirect in net/http
CVE-2025-46712
Erlang/OTP SSH Has Strict KEX Violations
CVE-2025-46686
Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. NOTE: this is disputed by the Supplier because abuse of the commands network protocol is not a violation of the Redis Security Model.
CVE-2025-4664
Chromium: CVE-2025-4664 Insufficient policy enforcement in Loader
CVE-2025-46569
OPA server Data API HTTP path injection of Rego
CVE-2025-46421
Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server
CVE-2025-46420
Libsoup: memory leak on soup_header_parse_quality_list() via soup-headers.c
CVE-2025-46394
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
CVE-2025-46334
GitHub: CVE-2025-46334 Git Malicious Shell Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-47162 Microsoft Office Remote Code Execution Vulnerability | CVSS3: 8.4 | 1% Низкий | около 1 года назад | |
CVE-2025-47161 Microsoft Defender for Endpoint Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-47160 Windows Shortcut Files Security Feature Bypass Vulnerability | CVSS3: 5.4 | 1% Низкий | около 1 года назад | |
CVE-2025-47159 Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
CVE-2025-47158 Azure DevOps Server Elevation of Privilege Vulnerability | 1% Низкий | около 1 года назад | ||
CVE-2025-46836 net-tools Stack-based Buffer Overflow vulnerability | CVSS3: 6.6 | 0% Низкий | 6 месяцев назад | |
CVE-2025-46835 GitHub: CVE-2025-46835 Git File Overwrite Vulnerability | 0% Низкий | около 1 года назад | ||
CVE-2025-46819 Redis is vulnerable to DoS via specially crafted LUA scripts | CVSS3: 6.3 | 1% Низкий | 10 месяцев назад | |
CVE-2025-46818 Redis: Authenticated users can execute LUA scripts as a different user | CVSS3: 6 | 1% Низкий | 8 месяцев назад | |
CVE-2025-46817 Lua library commands may lead to integer overflow and potential RCE | CVSS3: 7 | 4% Низкий | 10 месяцев назад | |
CVE-2025-4674 Unexpected command execution in untrusted VCS repositories in cmd/go | CVSS3: 8.6 | 0% Низкий | 12 месяцев назад | |
CVE-2025-4673 Sensitive headers not cleared on cross-origin redirect in net/http | CVSS3: 6.8 | 1% Низкий | 6 месяцев назад | |
CVE-2025-46712 Erlang/OTP SSH Has Strict KEX Violations | CVSS3: 3.7 | 1% Низкий | 4 дня назад | |
CVE-2025-46686 Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. NOTE: this is disputed by the Supplier because abuse of the commands network protocol is not a violation of the Redis Security Model. | 0% Низкий | 10 дней назад | ||
CVE-2025-4664 Chromium: CVE-2025-4664 Insufficient policy enforcement in Loader | 6% Низкий | больше 1 года назад | ||
CVE-2025-46569 OPA server Data API HTTP path injection of Rego | 0% Низкий | около 1 года назад | ||
CVE-2025-46421 Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server | CVSS3: 6.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-46420 Libsoup: memory leak on soup_header_parse_quality_list() via soup-headers.c | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-46394 In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences. | 0% Низкий | 8 месяцев назад | ||
CVE-2025-46334 GitHub: CVE-2025-46334 Git Malicious Shell Vulnerability | 0% Низкий | около 1 года назад |
Уязвимостей на страницу