8.7

CVSS4.0

CVE-2025-6939 - TOTOLINK A3002RU HTTP POST Request formWlSiteSurvey buffer overflow

A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteSurvey of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to la…

πŸ“… Published: July 1, 2025, 2:02 a.m. πŸ”„ Last Modified: July 1, 2025, 3:15 a.m.

4.4

CVSS4.0

CVE-2024-46993 - Electron Vulnerable to Heap Buffer Overflow in NativeImage::CreateFromPath

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 28.3.2, 29.3.3, and 30.0.3, the nativeImage.createFromPath() and nativeImage.createFromBuffer() functions call a function downstream that is vulnerable to a heap…

πŸ“… Published: July 1, 2025, 1:55 a.m. πŸ”„ Last Modified: July 1, 2025, 3:15 a.m.

7.8

CVSS3.1

CVE-2024-46992 - Electron ASAR Integrity bypass by just modifying the content

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 30.0.0-alpha.1 to before 30.0.5 and 31.0.0-alpha.1 to before 31.0.0-beta.1, Electron is vulnerable to an ASAR Integrity bypass. This only impacts apps that have the emb…

πŸ“… Published: July 1, 2025, 1:43 a.m. πŸ”„ Last Modified: July 1, 2025, 2:15 a.m.

9.7

CVSS3.1

CVE-2025-53095 - Sunshine application-wide CSRF in the UI leads to command injection as Administrator

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an authenticated user, can t…

πŸ“… Published: July 1, 2025, 1:33 a.m. πŸ”„ Last Modified: July 1, 2025, 2:15 a.m.

5.4

CVSS3.1

CVE-2025-53096 - Sunshine clickjacking in the UI leads to unauthorized actions being performed

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or disguised iframe. If…

πŸ“… Published: July 1, 2025, 1:33 a.m. πŸ”„ Last Modified: July 1, 2025, 2:15 a.m.

6.9

CVSS4.0

CVE-2025-6938 - code-projects Simple Pizza Ordering System editcus.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /editcus.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: July 1, 2025, 1:32 a.m. πŸ”„ Last Modified: July 1, 2025, 2:15 a.m.

8.2

CVSS4.0

CVE-2025-53003 - Janssen Config API returns results without scope verification

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This has a large internal surface attack area that exposes all sorts of information from the IDP including clients, users, scripts …

πŸ“… Published: July 1, 2025, 1:22 a.m. πŸ”„ Last Modified: July 1, 2025, 2:15 a.m.

6.1

CVSS3.1

CVE-2025-2141 - IBM System Storage Virtualization Engine TS7700 cross-site scripting

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115Β is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI th…

πŸ“… Published: July 1, 2025, 1:01 a.m. πŸ”„ Last Modified: July 1, 2025, 1:15 a.m.

5.4

CVSS3.1

CVE-2025-36056 - IBM System Storage Virtualization Engine TS7700 cross-site scripting

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115Β is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI th…

πŸ“… Published: July 1, 2025, 1 a.m. πŸ”„ Last Modified: July 1, 2025, 1:15 a.m.

8.9

CVSS4.0

CVE-2025-53005 - Dataease PostgreSQL Data Source JDBC Connection Parameters Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's PostgreSQL Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has b…

πŸ“… Published: July 1, 2025, 12:33 a.m. πŸ”„ Last Modified: July 1, 2025, 1:15 a.m.
Total resulsts: 299964
Page 2 of 29,997
Β« previous page Β» next page
Filters