5.7

CVSS3.1

CVE-2024-58257 -

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

📅 Published: Aug. 8, 2025, 3:15 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.

4.5

CVSS3.1

CVE-2024-58256 -

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

📅 Published: Aug. 8, 2025, 3:14 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.

2.3

CVSS4.0

CVE-2025-8708 - Antabot White-Jotter com.gm.wj.config.ShiroConfiguration ShiroConfiguration.java CookieRememberMeMa…

A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipulation with the input EVANNIGHTLY_WAOU leads …

📅 Published: Aug. 8, 2025, 2:32 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.

4.8

CVSS4.0

CVE-2025-8707 - Huuge Box App com.huuge.game.zjbox AndroidManifest.xml improper export of android application compo…

A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unknown part of the file AndroidManifest.xml of the component com.huuge.game.zjbox. The manipulation leads to improper export of android application components. Local access is requir…

📅 Published: Aug. 8, 2025, 2:02 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.

5.3

CVSS4.0

CVE-2025-8706 - Wanzhou WOES Intelligent Optimization Energy Saving System Energy Overview Module CreateFunctionLog…

A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /CommonSolution/CreateFunctionLog of the component Energy Overview Module. The manipulation of the argu…

📅 Published: Aug. 8, 2025, 1:32 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.

5.3

CVSS4.0

CVE-2025-8705 - Wanzhou WOES Intelligent Optimization Energy Saving System Energy Overview Module GetTargetConfig s…

A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Affected is an unknown function of the file /WEAS_HomePage/GetTargetConfig of the component Energy Overview Module. The manipulation of the argument BP_ProID leads to sql …

📅 Published: Aug. 8, 2025, 1:02 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.

5.3

CVSS4.0

CVE-2025-8704 - Wanzhou WOES Intelligent Optimization Energy Saving System Analysis Conclusion Query Module GetAlar…

A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This issue affects some unknown processing of the file /WEAS_AlarmResult/GetAlarmResultProcessList of the component Analysis Conclusion Query Module. The manipulation…

📅 Published: Aug. 8, 2025, 12:32 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.

9.1

CVSS3.1

CVE-2025-54887 - jwe: Missing AES-GCM authentication tag validation in encrypted JWEs

jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication tags of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. This puts users at risk becau…

📅 Published: Aug. 8, 2025, 12:06 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.

8.4

CVSS3.1

CVE-2025-54886 - skops: Card.get_model does not block arbitrary code execution

skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not contain any logic to prevent arbitrary code execution. The Card.get_model function supports both joblib and skops for model loading. When loading .sk…

📅 Published: Aug. 8, 2025, 12:03 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.

5.5

CVSS4.0

CVE-2025-54793 - Astro: Duplicate trailing slash feature can lead to Open Redirects

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users to arbitrary external domains by crafting URLs s…

📅 Published: Aug. 8, 2025, 12:02 a.m. 🔄 Last Modified: Aug. 8, 2025, 8:30 p.m.
Total resulsts: 304729
Page 12 of 30,473
« previous page » next page
Filters