7.5

CVSS3.1

CVE-2024-3884 - Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows…

πŸ“… Published: Dec. 3, 2025, 4:50 p.m. πŸ”„ Last Modified: April 1, 2026, 1:32 p.m.

9.3

CVSS4.0

CVE-2025-34319 - TOTOLINK N300RT <= V2.1.8-B20201030.1539 Boa formWsc RCE

TOTOLINK N300RT wireless router firmware versions prior toΒ V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vulnerability in the Boa formWsc handling functionality. An unauthenticated attacker can send specially crafted requests to trigger command execution via…

πŸ“… Published: Dec. 3, 2025, 4:49 p.m. πŸ”„ Last Modified: March 5, 2026, 12:03 p.m.

7.5

CVSS3.1

CVE-2024-32643 - Masa CMS vulnerable to authentication bypass with /tag/

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS will render the page regardless of group restrictions. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.

πŸ“… Published: Dec. 3, 2025, 4:43 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 3:37 p.m.

8.8

CVSS3.1

CVE-2024-32642 - Host header poisoning allows account takeover via password reset email

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.

πŸ“… Published: Dec. 3, 2025, 4:37 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 3:36 p.m.

5.4

CVSS4.0

CVE-2025-13492 - HP Image Assistant - Potential Escalation of Privilege

A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerability could potentially allow a local attacker to escalate privileges via a race condition when installing packages.

πŸ“… Published: Dec. 3, 2025, 4:33 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

9.8

CVSS3.1

CVE-2024-32641 - Masa CMS Vulnerable to Pre-Auth RCE via JSON API

Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluate…

πŸ“… Published: Dec. 3, 2025, 4:26 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 2:47 p.m.

1.3

CVSS4.0

CVE-2025-13751 - OpenVPN: OpenVPN: Local denial of service vulnerability in interactive service agent

Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.

πŸ“… Published: Dec. 3, 2025, 4:22 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 6:43 p.m.

7.7

CVSS3.1

CVE-2025-7044 - Privilege Escalation in MAAS via Websocket Request Manipulation

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-…

πŸ“… Published: Dec. 3, 2025, 3:45 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 9:01 p.m.

10

CVSS3.1

CVE-2025-55182 - next: From CVEorg collector

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes paylo…

πŸ“… Published: Dec. 3, 2025, 3:40 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

0.0

CVE-2025-13965 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12500. Reason: This candidate is a reservation duplicate of CVE-2025-12500. Notes: All CVE users should reference CVE-2025-12500 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

πŸ“… Published: Dec. 3, 2025, 3:16 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:08 p.m.
Total resulsts: 343996
Page 2321 of 34,400
Β« previous page Β» next page
Filters