4.8

CVSS4.0

CVE-2025-8846 - NASM Netwide Assember parser.c parse_line stack-based overflow

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Aug. 11, 2025, 12:32 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 7:41 a.m.

4.8

CVSS4.0

CVE-2025-8672 - TCC Bypass via Inherited Permissions in Bundled Interpreter in GIMP.app

MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the applicationโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 12:21 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 7:47 a.m.

4.8

CVSS4.0

CVE-2025-8845 - NASM Netwide Assember nasm.c assemble_file stack-based overflow

A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be usโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 12:02 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 1:43 p.m.

4.8

CVSS4.0

CVE-2025-8844 - NASM Netwide Assember preproc.c parse_smacro_template null pointer dereference

A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Aug. 11, 2025, 11:32 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 7:41 a.m.

4.8

CVSS4.0

CVE-2025-8843 - NASM Netwide Assember outmacho.c macho_no_dead_strip heap-based overflow

A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Aug. 11, 2025, 11:02 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

4.8

CVSS4.0

CVE-2025-8842 - NASM Netwide Assember preproc.c do_directive use after free

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Aug. 11, 2025, 10:32 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

5.3

CVSS4.0

CVE-2025-8841 - zlt2000 microservices-platform FileController.java upload unrestricted upload

A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads to unrestricted upload. The attack can be laโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:02 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

5.3

CVSS4.0

CVE-2025-8840 - jshERP Endpoint deleteBatch improper authorization

A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of the argument ids leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosedโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 9:32 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

9.3

CVSS4.0

CVE-2025-8853 - 2100 Technology๏ฝœOfficial Document Management System - Authentication Bypass

Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.

๐Ÿ“… Published: Aug. 11, 2025, 9:04 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.

5.3

CVSS4.0

CVE-2025-8839 - jshERP Endpoint addUser improper authorization

A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be โ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 9:02 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 11:47 a.m.
Total resulsts: 304921
Page 13 of 30,493
ยซ previous page ยป next page
Filters