7.6
CVE-2025-69195 - Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlβ¦
A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker can exploit this by providing a specially crafted Uβ¦
5.5
CVE-2025-66866 - binutils: BinUtils: Denial of Service via crafted PE file
An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
6.5
CVE-2025-60458 -
UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.
7.5
CVE-2025-66877 -
Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.
7.5
CVE-2025-66869 -
Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.
7.5
CVE-2025-66862 - binutils: heap-based buffer over-read in gnu_special() in cplus-dem.c
A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
6.1
CVE-2025-57462 -
Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file.
9.8
CVE-2024-25182 -
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
9.8
CVE-2024-27480 -
givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
6.1
CVE-2025-65442 -
DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrary JavaScript code or disclose sensitive information (e.g., user session cookies) via a crafted "wvstest" parameter in the URL or malicious script injection into window.localStoragβ¦