6.7

CVSS4.0

CVE-2025-9043 -

The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Search Path or Element. An attacker with write permissions to the root could place a malicious Program.e…

πŸ“… Published: Aug. 14, 2025, 4:27 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 4:27 p.m.

5.3

CVSS4.0

CVE-2025-9039 - Information Disclosure in Amazon ECS Container Agent

We identified an issue in the Amazon ECS agent where, under certain conditions, an introspection server could be accessed off-host by another instance if the instances are in the same security group or if their security groups allow incoming connections that include the port where the server is hos…

πŸ“… Published: Aug. 14, 2025, 4:15 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 4:15 p.m.

7

CVSS3.1

CVE-2025-54867 - Youki Symlink Following Vulnerability

Youki is a container runtime written in Rust. Prior to version 0.5.5, if /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem. This issue has been patched in version 0.5.5.

πŸ“… Published: Aug. 14, 2025, 4:08 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 4:08 p.m.

6.9

CVSS4.0

CVE-2025-8967 - itsourcecode Online Tour and Travel Management System packages.php sql injection

A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/packages.php. The manipulation of the argument pname leads to sql injection. It is possible to launch the attack remotely. The exploit has been …

πŸ“… Published: Aug. 14, 2025, 4:02 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 4:02 p.m.

6.2

CVSS3.1

CVE-2025-54389 - AIDE improper output neutralization vulnerability

AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization vulnerability in AIDE. An attacker can craft a malicious filename by including terminal escape sequences to hide the addition or removal of the file from the report and/or tampe…

πŸ“… Published: Aug. 14, 2025, 3:53 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 3:53 p.m.

6.2

CVSS3.1

CVE-2025-54409 - AIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (loca…

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a k…

πŸ“… Published: Aug. 14, 2025, 3:52 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 3:52 p.m.

5.3

CVSS3.1

CVE-2025-33142 - IBM WebSphere Application Server information disclosure

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

πŸ“… Published: Aug. 14, 2025, 3:41 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 3:41 p.m.

5.3

CVSS3.1

CVE-2025-36047 - IBM WebSphere Application Server Liberty denial of service

IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

πŸ“… Published: Aug. 14, 2025, 3:38 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 3:38 p.m.

6.9

CVSS4.0

CVE-2025-8966 - itsourcecode Online Tour and Travel Management System tax.php sql injection

A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/tax.php. The manipulation of the argument tname leads to sql injection. The attack may be initiated remotely. The exploit has been disclos…

πŸ“… Published: Aug. 14, 2025, 3:32 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 3:32 p.m.

5.3

CVSS4.0

CVE-2025-8965 - linlinjava litemall Endpoint AdminStorageController.java create unrestricted upload

A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the component Endpoint. The manipulation of the argument File leads to unre…

πŸ“… Published: Aug. 14, 2025, 3:32 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 3:32 p.m.
Total resulsts: 305784
Page 22 of 30,579
Β« previous page Β» next page
Filters