9.8

CVSS3.1

CVE-2025-29085 -

SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2025-29063 -

An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2025-29062 -

An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 4:15 p.m.

8.8

CVSS3.1

CVE-2025-22924 -

OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 4:15 p.m.

8.8

CVSS3.1

CVE-2025-22923 -

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 4:15 p.m.

5.5

CVSS3.1

CVE-2025-21990 - drm/amdgpu: NULL-check BO's backing store when determining GFX12 PTE flags

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: NULL-check BO's backing store when determining GFX12 PTE flags PRT BOs may not have any backing store, so bo->tbo.resource will be NULL. Check for that before dereferencing. (cherry picked from commit 3e3fcd29b505ceb…

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 2:58 p.m.

5.5

CVSS3.1

CVE-2025-21989 - drm/amd/display: fix missing .is_two_pixels_per_container

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix missing .is_two_pixels_per_container Starting from 6.11, AMDGPU driver, while being loaded with amdgpu.dc=1, due to lack of .is_two_pixels_per_container function in dce60_tg_funcs, causes a NULL pointer deref…

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 2:58 p.m.

7.2

CVSS3.1

CVE-2025-30090 -

mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers, because JavaScript payloads are mishandled after $encoded has been set to true.

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 2:58 p.m.

5.8

CVSS3.1

CVE-2025-27556 - django: Django DoS Unicode Attack

An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack vi…

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 10:15 p.m.

5.5

CVSS3.1

CVE-2025-21991 - x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes

In the Linux kernel, the following vulnerability has been resolved: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes Currently, load_microcode_amd() iterates over all NUMA nodes, retrieves their CPU masks and unconditionally accesses per-CPU data for the first CPU of each …

πŸ“… Published: April 2, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 2:58 p.m.
Total resulsts: 288418
Page 24 of 28,842
Β« previous page Β» next page
Filters