0.0

CVE-2025-52395 -

An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint that fails to validate the identity of the requester properly

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 3:47 p.m.

0.0

CVE-2025-47184 -

An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 7.0.1p02 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escalation via a crafted ISys XML message.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 12:52 p.m.

0.0

CVE-2025-52194 -

A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential co…

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 2:23 p.m.

0.0

CVE-2025-55366 -

Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 1:40 p.m.

8.8

CVSS3.1

CVE-2025-9141 - vllm: quen3: RCE in vllm tool call parser for qwen3coder

A vulnerability was found in vLLM's Qwen3 Coder tool parser. Since this parser uses Python's eval() function, it poses a risk of arbitrary code execution. This vulnerability appears during the parameter conversion process when the parser attempts to handle complex data types.

πŸ“… Published: Aug. 20, 2025, 11:37 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:37 p.m.

5.3

CVSS4.0

CVE-2025-9264 - Xuxueli xxl-job Jobs JobInfoController.java remove resource injection

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource id…

πŸ“… Published: Aug. 20, 2025, 11:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:32 p.m.

5.3

CVSS4.0

CVE-2025-9263 - Xuxueli xxl-job JobLogController.java getJobsByGroup resource injection

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to improper control of resource identifiers. T…

πŸ“… Published: Aug. 20, 2025, 11:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:02 p.m.

6.3

CVSS4.0

CVE-2025-9262 - wong2 mcp-cli oAuth provider.js redirectToAuthorization os command injection

A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component oAuth Handler. This manipulation causes os command injection. The attack may be initiated remotely. The attack is considered to have high complexity. T…

πŸ“… Published: Aug. 20, 2025, 11:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:02 p.m.

8.7

CVSS4.0

CVE-2025-9253 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_doSpecifySiteSurvey stack-based overflow

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function RP_doSpecifySiteSurvey of the file /goform/RP_doSpecifySiteSurvey. The manipulation of the argument…

πŸ“… Published: Aug. 20, 2025, 10:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 10:32 p.m.

8.7

CVSS4.0

CVE-2025-9252 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 DisablePasswordAlertRedirect stack-based overflow

A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function DisablePasswordAlertRedirect of the file /goform/DisablePasswordAlertRedirect. Executing manipulation o…

πŸ“… Published: Aug. 20, 2025, 10:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 10:02 p.m.
Total resulsts: 306552
Page 14 of 30,656
Β« previous page Β» next page
Filters