0.0

CVE-2025-43933 -

fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 4:15 p.m.

0.0

CVE-2025-43931 -

flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 4:15 p.m.

0.0

CVE-2025-26780 -

An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Service via a malformed PDCP packet.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 4:15 p.m.

0.0

CVE-2025-45479 -

Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content into a container.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 4:15 p.m.

0.0

CVE-2025-43930 -

Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 3:15 p.m.

0.0

CVE-2023-51232 -

Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 4:15 p.m.

0.0

CVE-2025-43932 -

JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 4:15 p.m.

0.0

CVE-2025-52492 -

A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credentials for the Twilio API. A remote attacker who obtains a copy of the firmware can extract these credentials. This could allow the attacker to gain unau…

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 4:15 p.m.

6.3

CVSS4.0

CVE-2025-7099 - BoyunCMS Installation install2.php deserialization

A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file install/install2.php of the component Installation Handler. The manipulation of the argument db_host leads to deserialization. The attack …

πŸ“… Published: July 6, 2025, 11:32 p.m. πŸ”„ Last Modified: July 7, 2025, 4:15 p.m.

6.3

CVSS4.0

CVE-2025-7098 - Comodo Internet Security Premium File Name path traversal

A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function of the component File Name Handler. The manipulation of the argument name/folder leads to path traversal. It is possible to launch the attack remotely. The c…

πŸ“… Published: July 6, 2025, 11:02 p.m. πŸ”„ Last Modified: July 7, 2025, 4:15 p.m.
Total resulsts: 300723
Page 17 of 30,073
Β« previous page Β» next page
Filters