9.3

CVSS4.0

CVE-2024-58299 - PCMan FTP Server 2.0 Remote Buffer Overflow via 'pwd' Command

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.

๐Ÿ“… Published: Dec. 12, 2025, 7:56 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2024-14010 - Typora 1.7.4 OS Command Injection via Export PDF Preferences

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

๐Ÿ“… Published: Dec. 12, 2025, 7:55 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-67734 - Frappe Authenticated Users can Execute JavaScript through its Job Form

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposing users to an XSS attack. The script could then be executed iโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 7:48 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 9:34 p.m.

8.7

CVSS4.0

CVE-2025-14572 - UTT ่ฟ›ๅ– 512W formWebAuthGlobalConfig memory corruption

A vulnerability was found in UTT ่ฟ›ๅ– 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAuthGlobalConfig. Performing manipulation of the argument hidcontact results in memory corruption. Remote exploitation of the attack is possible. The exploit has been made public andโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 8:22 p.m.

8.6

CVSS3.1

CVE-2025-8083 - Vuetify Prototype Pollution via Preset options

The Preset configuration https://v2.vuetifyjs.com/en/features/presets ย feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html ย due to the internal 'mergeDeep' utility function used to merge options witโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 7:29 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-14373 -

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: Dec. 12, 2025, 7:20 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 3:33 p.m.

6.1

CVSS3.1

CVE-2025-14372 -

Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: Dec. 12, 2025, 7:20 p.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 3:34 p.m.

8.8

CVSS3.1

CVE-2025-14174 - Google Chrome: chromium: Out of bounds memory access via crafted HTML page

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Dec. 12, 2025, 7:20 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

6.3

CVSS3.1

CVE-2025-8082 - Vuetify XSS via unsanitized 'titleDateFormat' in 'VDatePicker'

Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page.ย This can lead to a Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss ย attack. The vulnerability occurs because theย 'title-date-format' proโ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 6:33 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-14571 - projectworlds Advanced Library Management System borrow_book.php sql injection

A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /borrow_book.php. Such manipulation of the argument roll_number leads to sql injection. The attack may be launched remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Dec. 12, 2025, 6:32 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 5:47 a.m.
Total resulsts: 349182
Page 2633 of 34,919
ยซ previous page ยป next page
Filters