2.5
CVE-2025-66861 - binutils: out-of-bounds read in d_unqualified_name() in cp-demangle.c
An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.
7.5
CVE-2025-67254 -
NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.
8.8
CVE-2024-30855 -
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.
5.5
CVE-2025-66864 - binutils: NULL pointer dereference in d_print_comp_inner() in cp-demangle.c
An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
9.8
CVE-2025-57460 -
File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
7.5
CVE-2024-25183 -
givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.
9.1
CVE-2024-25181 -
A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.
8.8
CVE-2025-67255 -
In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.
7.6
CVE-2025-69195 - Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlβ¦
A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker can exploit this by providing a specially crafted Uβ¦
5.5
CVE-2025-66866 - binutils: BinUtils: Denial of Service via crafted PE file
An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.