4.9

CVSS3.1

CVE-2025-43954 -

QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

6.1

CVSS3.1

CVE-2020-36844 -

The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.1

CVSS3.1

CVE-2025-43929 -

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

2.9

CVSS3.1

CVE-2025-43966 -

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

2.9

CVSS3.1

CVE-2025-43961 - LibRaw: Out-of-Bounds Read in Fujifilm 0xf00c Tag Parser in LibRaw

In LibRaw before 0.21.4, metadata/tiff.cpp has an out-of-bounds read in the Fujifilm 0xf00c tag parser.

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

2.9

CVSS3.1

CVE-2025-43967 -

libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

2.9

CVSS3.1

CVE-2025-43964 - LibRaw: Improper Validation of Specified Quantity in Input in LibRaw

In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.3

CVSS3.1

CVE-2020-36845 -

The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitrary https URL.

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

2.2

CVSS3.1

CVE-2025-43955 -

TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.8

CVSS3.1

CVE-2025-43928 -

In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.

๐Ÿ“… Published: April 20, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:33 p.m.
Total resulsts: 291097
Page 14 of 29,110
ยซ previous page ยป next page
Filters