4.4

CVSS3.1

CVE-2025-30101 -

Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to denial of service and information tampering.

πŸ“… Published: May 8, 2025, 5:44 p.m. πŸ”„ Last Modified: May 8, 2025, 6:43 p.m.

5.5

CVSS3.1

CVE-2025-30102 -

Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.

πŸ“… Published: May 8, 2025, 5:40 p.m. πŸ”„ Last Modified: May 8, 2025, 6:55 p.m.

7.2

CVSS3.1

CVE-2024-13009 - Eclipse Jetty GZIP buffer release

In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.

πŸ“… Published: May 8, 2025, 5:29 p.m. πŸ”„ Last Modified: May 8, 2025, 6:56 p.m.

3.1

CVSS3.1

CVE-2025-4132 - Unvalidated Redirect Vulnerability on Rapid7.com

Rapid7 Corporate Website prior to May 2nd 2025, suffered from a URL Redirection to Untrusted Site ('Open Redirect') vulnerability whereby, due to misconfigured headers, an attacker could successfully redirect users to a malicious site of their control. This vulnerability has been fixed as of May 2…

πŸ“… Published: May 8, 2025, 3:10 p.m. πŸ”„ Last Modified: May 8, 2025, 6:23 p.m.

5.9

CVSS3.1

CVE-2025-4207 - PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails…

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 1…

πŸ“… Published: May 8, 2025, 2:22 p.m. πŸ”„ Last Modified: May 9, 2025, 6:16 p.m.

8.7

CVSS4.0

CVE-2024-6648 - Path Traversal in AP Page Builder

Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.

πŸ“… Published: May 8, 2025, 12:16 p.m. πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

6.3

CVSS4.0

CVE-2025-3506 - Potentially senitive path exposed via unauthenticated http route

Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets.

πŸ“… Published: May 8, 2025, 11:24 a.m. πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

6.1

CVSS3.1

CVE-2025-2806 - tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'data'

The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the β€˜data’ parameter in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers …

πŸ“… Published: May 8, 2025, 11:23 a.m. πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

6.4

CVSS3.1

CVE-2025-3468 - NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) S…

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_html and form_fields parameters in all versions up to, and including, 8.9.1 due to insufficient input sanitization and output escaping. This makes it p…

πŸ“… Published: May 8, 2025, 11:13 a.m. πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

6.4

CVSS3.1

CVE-2025-3862 - Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Paramet…

Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abo…

πŸ“… Published: May 8, 2025, 11:13 a.m. πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.
Total resulsts: 293439
Page 26 of 29,344
Β« previous page Β» next page
Filters