5.3

CVSS4.0

CVE-2025-7075 - BlackVue Dashcam 590X HTTP Endpoint upload.cgi unrestricted upload

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /upload.cgi of the component HTTP Endpoint. The manipulation leads to unrestricted upload. The attack needs to be done within t…

πŸ“… Published: July 5, 2025, 11:32 p.m. πŸ”„ Last Modified: July 6, 2025, 12:15 a.m.

5.3

CVSS4.0

CVE-2025-7074 - vercel hyper rimraf-standalone.js ignoreMap redos

A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotel…

πŸ“… Published: July 5, 2025, 9:02 a.m. πŸ”„ Last Modified: July 5, 2025, 9:15 a.m.

5.9

CVSS3.1

CVE-2025-53605 - protobuf: Protobuf: Uncontrolled Recursion Vulnerability

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: July 5, 2025, 1:15 a.m.

4.1

CVSS3.1

CVE-2023-50786 -

Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: July 5, 2025, 4:15 a.m.

6.7

CVSS3.1

CVE-2025-47228 -

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands via crafted HTTP requests.

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: July 5, 2025, 3:15 a.m.

7.5

CVSS3.1

CVE-2025-47227 -

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeov…

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: July 5, 2025, 3:15 a.m.

0.0

CVE-2024-58254 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-11738. Reason: This candidate is a duplicate of CVE-2024-11738. Notes: All CVE users should reference CVE-2024-11738 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: July 5, 2025, 4:15 a.m.

4

CVSS3.1

CVE-2025-53604 -

The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: July 5, 2025, 1:15 a.m.

7.5

CVSS3.1

CVE-2025-53603 -

In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: July 5, 2025, 1:15 a.m.

9.4

CVSS3.1

CVE-2025-48952 - NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP

NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to bypass password verification using SHA-256 magic hashes, due to loose comparison in PHP. In vulnerable versions of the application, a password comparis…

πŸ“… Published: July 4, 2025, 10:12 p.m. πŸ”„ Last Modified: July 4, 2025, 11:15 p.m.
Total resulsts: 300627
Page 11 of 30,063
Β« previous page Β» next page
Filters