5.3

CVSS3.1

CVE-2024-52903 - IBM Db2 denial of service

IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

πŸ“… Published: May 1, 2025, 10:15 p.m. πŸ”„ Last Modified: May 2, 2025, 2:35 p.m.

6

CVSS3.1

CVE-2025-1333 - IBM MQ Operator information disclosure

IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose sensitive information to…

πŸ“… Published: May 1, 2025, 10:07 p.m. πŸ”„ Last Modified: May 2, 2025, 2:36 p.m.

6.9

CVSS4.0

CVE-2025-4180 - PCMan FTP Server TRACE Command buffer overflow

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function of the component TRACE Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and …

πŸ“… Published: May 1, 2025, 10 p.m. πŸ”„ Last Modified: May 2, 2025, 5:24 p.m.

5.3

CVSS4.0

CVE-2025-4178 - xiaowei1118 java_server File Upload API FoodController.java path traversal

A vulnerability was found in xiaowei1118 java_server up to 11a5bac8f4ba1c17e4bc1b27cad6d24868500e3a on Windows and classified as critical. This issue affects some unknown processing of the file /src/main/java/com/changyu/foryou/controller/FoodController.java of the component File Upload API. The ma…

πŸ“… Published: May 1, 2025, 10 p.m. πŸ”„ Last Modified: May 2, 2025, 5:25 p.m.

6.9

CVSS4.0

CVE-2025-4176 - PHPGurukul Blood Bank & Donor Management System request-received-bydonar.php sql injection

A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as critical. This vulnerability affects unknown code of the file /admin/request-received-bydonar.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated …

πŸ“… Published: May 1, 2025, 9:31 p.m. πŸ”„ Last Modified: May 2, 2025, 5:29 p.m.

6.5

CVSS3.1

CVE-2025-27365 - IBM MQ Operator denial of service

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10Β  Client connecting to a MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

πŸ“… Published: May 1, 2025, 9:24 p.m. πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

8.5

CVSS4.0

CVE-2025-43595 - MSP360 Backup for Linux insecure filesystem permissions

An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).

πŸ“… Published: May 1, 2025, 9:12 p.m. πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

5.3

CVSS4.0

CVE-2025-4175 - AlanBinu007 Spring-Boot-Advanced-Projects Upload Profile API Endpoint UserProfileController.jav upl…

A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. This affects the function uploadUserProfileImage of the file /Spring-Boot-Advanced-Projects-main/Project-4.SpringBoot-AWS-S3/backend/src/main/java/com/urunov/profile/UserProfileCon…

πŸ“… Published: May 1, 2025, 8:31 p.m. πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

7.4

CVSS4.0

CVE-2025-46569 - OPA server Data API HTTP path injection of Rego

Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API for reading and writing documents. Requesting a virtual document through the Data API entails policy evaluation, where a Rego query containing a singl…

πŸ“… Published: May 1, 2025, 7:32 p.m. πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

6.9

CVSS4.0

CVE-2025-4174 - PHPGurukul COVID19 Testing Management System login.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. …

πŸ“… Published: May 1, 2025, 7 p.m. πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.
Total resulsts: 292440
Page 19 of 29,244
Β« previous page Β» next page
Filters