CVE Severity Distribution (Last 30 Days)
Found 10 CVEs in the last 30 days.
CVE-2025-57772
CRITICAL
CVSS: 9.8
EPSS: 9.3%
CWE-94
T1059
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If the JDBC URL meets criteria, the getJdbcUrl method is returned, which acts as the getter for the JdbcUrl parameter provided. This bypasses H2's filtering logic and returns the H2 JDBC URL, allowing the "driver":"org.h2.Driver" to specify the H2 driver for the JDBC connection. The vulnerability has been fixed in version 2.10.12.
Published: 2025-08-25
CVE-2025-57773
CRITICAL
CVSS: 9.8
EPSS: 8.3%
CWE-94
CWE-502
T1059
T1203
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserialization attack, writing to various files. This vulnerability requires commons-collections 4.x and aspectjweaver-1.9.22.jar. The vulnerability has been fixed in version 2.10.12.
Published: 2025-08-25
CVE-2025-57771
HIGH
CVSS: 8.1
EPSS: 0.7%
CWE-78
T1059
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fails to properly handle process substitution and single ampersand characters in the command parsing logic for auto-execute commands. If a user has enabled auto-approved execution for a command such as ls, an attacker who can submit crafted prompts to the agent may inject arbitrary commands to be executed alongside the intended command. Exploitation requires attacker access to submit prompts and for the user to have enabled auto-approved command execution, which is disabled by default. This vulnerability could allow an attacker to execute arbitrary code. The issue is fixed in version 3.25.5.
Published: 2025-08-22
CVE-2025-57774
HIGH
CVSS: 7.8
EPSS: 0.3%
CWE-1285
CWE-787
T1203
There is an out of bounds write vulnerability due to improper bounds checking resulting in invalid data when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.
Published: 2025-09-02
CVE-2025-57775
HIGH
CVSS: 7.8
EPSS: 0.3%
CWE-1285
CWE-787
T1203
There is a heap-based Buffer Overflow vulnerability due to improper bounds checking when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.
Published: 2025-09-02
CVE-2025-57776
HIGH
CVSS: 7.8
EPSS: 0.3%
CWE-1285
CWE-787
T1203
There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.
Published: 2025-09-02
CVE-2025-57777
HIGH
CVSS: 7.8
EPSS: 0.3%
CWE-1285
CWE-787
T1203
There is an out of bounds write vulnerability due to improper bounds checking in displ2.dll when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.
Published: 2025-09-02
CVE-2025-57778
HIGH
CVSS: 7.8
EPSS: 0.3%
CWE-1285
CWE-787
T1203
There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid source address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.
Published: 2025-09-02
CVE-2025-5777
HIGH
CVSS: 7.5
EPSS: 100.0%
VulnCheck KEV
Weaponized
ExploitDB
CWE-125
CWE-908
CWE-457
T1005
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Published: 2025-06-17
CVE-2025-57770
MEDIUM
CVSS: 5.3
EPSS: 0.4%
CWE-203
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Versions 4.0.0 to 4.0.2, 3.0.0 to 3.3.6, and all versions prior to 2.71.15 are vulnerable to a username enumeration issue in the login interface. The login UI includes a security feature, Ignoring unknown usernames, that is intended to prevent username enumeration by returning a generic response for both valid and invalid usernames. This vulnerability allows an unauthenticated attacker to bypass this protection by submitting arbitrary userIDs to the select account page and distinguishing between valid and invalid accounts based on the system's response. For effective exploitation, an attacker needs to iterate through possible userIDs, but the impact can be limited by implementing rate limiting or similar measures. The issue has been patched in versions 4.0.3, 3.4.0, and 2.71.15.
Published: 2025-08-22