6.9

CVSS4.0

CVE-2025-4262 - PHPGurukul Online DJ Booking Management System user-search.php sql injection

A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/user-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. Th…

πŸ“… Published: May 5, 2025, 3:31 a.m. πŸ”„ Last Modified: May 7, 2025, 4:32 p.m.

4.8

CVSS4.0

CVE-2025-4261 - GAIR-NLP factool tool.py run_single code injection

A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as critical. This affects the function run_single of the file factool/factool/math/tool.py. The manipulation leads to code injection. The attack needs to be approached locally. The e…

πŸ“… Published: May 5, 2025, 3 a.m. πŸ”„ Last Modified: May 5, 2025, 8:54 p.m.

5.5

CVSS3.1

CVE-2025-20665 -

In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device identifier with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09555228; Issue ID: MSV-2760.

πŸ“… Published: May 5, 2025, 2:49 a.m. πŸ”„ Last Modified: May 12, 2025, 6:15 p.m.

5.7

CVSS3.1

CVE-2025-20670 -

In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with User execution privileges needed. User interaction is needed for exploitation. Pat…

πŸ“… Published: May 5, 2025, 2:49 a.m. πŸ”„ Last Modified: May 12, 2025, 6:15 p.m.

6.7

CVSS3.1

CVE-2025-20668 -

In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09625562; Issue ID: MSV-3027.

πŸ“… Published: May 5, 2025, 2:49 a.m. πŸ”„ Last Modified: May 7, 2025, 3:15 p.m.

6.4

CVSS3.1

CVE-2025-20671 -

In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09698599; Issue ID: MSV-3228.

πŸ“… Published: May 5, 2025, 2:49 a.m. πŸ”„ Last Modified: May 7, 2025, 3:15 p.m.

7.5

CVSS3.1

CVE-2025-20667 -

In Modem, there is a possible information disclosure due to incorrect error handling. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploi…

πŸ“… Published: May 5, 2025, 2:49 a.m. πŸ”„ Last Modified: May 12, 2025, 6:15 p.m.

7.5

CVSS3.1

CVE-2025-20666 -

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: …

πŸ“… Published: May 5, 2025, 2:49 a.m. πŸ”„ Last Modified: May 12, 2025, 6:15 p.m.

5.3

CVSS4.0

CVE-2025-4260 - zhangyanbo2007 youkefu TemplateController.java impsave deserialization

A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads to deserialization. The attack may be launche…

πŸ“… Published: May 5, 2025, 2:31 a.m. πŸ”„ Last Modified: May 5, 2025, 8:54 p.m.

5.3

CVSS4.0

CVE-2025-4259 - newbee-mall UploadController.java upload unrestricted upload

A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be launched rem…

πŸ“… Published: May 5, 2025, 2 a.m. πŸ”„ Last Modified: May 5, 2025, 8:54 p.m.
Total resulsts: 293599
Page 105 of 29,360
Β« previous page Β» next page
Filters