Количество 26 125
Количество 26 125
CVE-2025-27220
In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
CVE-2025-27210
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.
CVE-2025-27152
Possible SSRF and Credential Leakage via Absolute URL in axios Requests
CVE-2025-27151
redis-check-aof may lead to stack overflow and potential RCE
CVE-2025-27144
Go JOSE's Parsing Vulnerable to Denial of Service
CVE-2025-27113
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
CVE-2025-26688
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
CVE-2025-26687
Win32k Elevation of Privilege Vulnerability
CVE-2025-26686
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2025-26685
Microsoft Defender for Identity Spoofing Vulnerability
CVE-2025-26684
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2025-26683
Azure Playwright Elevation of Privilege Vulnerability
CVE-2025-26682
ASP.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2025-26681
Win32k Elevation of Privilege Vulnerability
CVE-2025-26680
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2025-26679
RPC Endpoint Mapper Service Elevation of Privilege Vulnerability
CVE-2025-26678
Windows Defender Application Control Security Feature Bypass Vulnerability
CVE-2025-26677
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
CVE-2025-26676
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-27220 In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method. | CVSS3: 4 | 1% Низкий | 6 дней назад | |
CVE-2025-27219 In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies. | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
CVE-2025-27210 An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API. | 10% Низкий | 12 дней назад | ||
CVE-2025-27152 Possible SSRF and Credential Leakage via Absolute URL in axios Requests | 1% Низкий | 12 месяцев назад | ||
CVE-2025-27151 redis-check-aof may lead to stack overflow and potential RCE | CVSS3: 4.7 | 1% Низкий | около 1 года назад | |
CVE-2025-27144 Go JOSE's Parsing Vulnerable to Denial of Service | 0% Низкий | больше 1 года назад | ||
CVE-2025-27113 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c. | CVSS3: 2.9 | 1% Низкий | больше 1 года назад | |
CVE-2025-26688 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-26687 Win32k Elevation of Privilege Vulnerability | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-26686 Windows TCP/IP Remote Code Execution Vulnerability | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-26685 Microsoft Defender for Identity Spoofing Vulnerability | 1% Низкий | больше 1 года назад | ||
CVE-2025-26684 Microsoft Defender Elevation of Privilege Vulnerability | CVSS3: 6.7 | 0% Низкий | больше 1 года назад | |
CVE-2025-26683 Azure Playwright Elevation of Privilege Vulnerability | 1% Низкий | больше 1 года назад | ||
CVE-2025-26682 ASP.NET Core and Visual Studio Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | больше 1 года назад | |
CVE-2025-26681 Win32k Elevation of Privilege Vulnerability | CVSS3: 6.7 | 1% Низкий | больше 1 года назад | |
CVE-2025-26680 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | больше 1 года назад | |
CVE-2025-26679 RPC Endpoint Mapper Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-26678 Windows Defender Application Control Security Feature Bypass Vulnerability | CVSS3: 8.4 | 1% Низкий | больше 1 года назад | |
CVE-2025-26677 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | больше 1 года назад | |
CVE-2025-26676 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | CVSS3: 6.5 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу