8.3

CVSS3.1

CVE-2025-6633 - RBG File Parsing Out-of-Bounds Write Vulnerability

A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

πŸ“… Published: Aug. 6, 2025, 8:43 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 3:55 a.m.

8.7

CVSS4.0

CVE-2025-7769 - Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy …

Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary com…

πŸ“… Published: Aug. 6, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 9:26 p.m.

5.3

CVSS3.1

CVE-2025-6632 - PSD File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Aug. 6, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 9:26 p.m.

7.5

CVSS3.1

CVE-2025-47908 - Denial of service via malicious preflight requests in github.com/rs/cors

Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue load on the middleware/server as an attempt…

πŸ“… Published: Aug. 6, 2025, 8:41 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 9:26 p.m.

9.3

CVSS4.0

CVE-2025-7768 - Use of Hard-coded Credentials in Tigo Energy Cloud Connect Advanced

Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings, disrupting solar ene…

πŸ“… Published: Aug. 6, 2025, 8:28 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 9:26 p.m.

3.5

CVSS3.1

CVE-2025-38746 -

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

πŸ“… Published: Aug. 6, 2025, 7:53 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 7:11 a.m.

7.8

CVSS3.1

CVE-2025-38747 -

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.

πŸ“… Published: Aug. 6, 2025, 7:48 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 7:11 a.m.

5.3

CVSS4.0

CVE-2025-8667 - SkyworkAI DeepResearchAgent tools.py from_mcp os command injection

A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2. Affected is the function from_code/from_dict/from_mcp of the file src/tools/tools.py. The manipulation leads to os command injection. It is possible to launch …

πŸ“… Published: Aug. 6, 2025, 6:02 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:27 p.m.

5.3

CVSS4.0

CVE-2025-8665 - agno-agi agno Model Context Protocol mcp.py MultiMCPTools os command injection

A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the function MCPTools/MultiMCPTools in the library libs/agno/agno/tools/mcp.py of the component Model Context Protocol Handler. The manipulation of the argument command leads to os com…

πŸ“… Published: Aug. 6, 2025, 5:02 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:23 p.m.

5.4

CVSS3.1

CVE-2025-20215 - Cisco Webex Meeting Client Join Certificate Validation Vulnerability

A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provided the requisite conditions were satisfied. Cisco has addressed this vulnerabil…

πŸ“… Published: Aug. 6, 2025, 4:17 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 7:11 a.m.
Total resulsts: 304731
Page 24 of 30,474
Β« previous page Β» next page
Filters