7.8

CVSS3.1

CVE-2025-61662 - Grub2: missing unregister call for gettext command may lead to use-after-free

A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condition by invoking the orphaned command, causing the application…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 4:30 p.m.

4.9

CVSS3.1

CVE-2025-61663 - Grub2: missing unregister call for normal commands may lead to use-after-free

A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the normal command is not properly unregistered when the module is unloaded. An attacker who can execute this comman…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-63228 -

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this by sending a crafted POST request with a malicious file (e.g., a PHP webshell) to the server. The upload…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 2:44 p.m.

9.8

CVSS3.1

CVE-2025-63994 -

An arbitrary file upload vulnerability in the /php/UploadHandler.php component of RichFilemanager v2.7.6 allows attackers to execute arbitrary code via uploading a crafted file.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:04 a.m.

6.1

CVSS3.1

CVE-2025-63828 -

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 2:02 p.m.

9.8

CVSS3.1

CVE-2025-63695 -

DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 7:04 p.m.

7.5

CVSS3.1

CVE-2025-63955 -

A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of …

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 5:27 p.m.

6.5

CVSS3.1

CVE-2025-63604 -

A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input validation in the execute_query method. The vulnerability stems from the exposure of dangerous Python built-in functions (__import__, getattr, hasatt…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 2:23 a.m.

8.4

CVSS3.1

CVE-2025-60455 -

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:02 p.m.

6.5

CVSS3.1

CVE-2025-63258 -

A remote command execution (RCE) vulnerability was discovered in all H3C ERG3/ERG5 series routers and XiaoBei series routers, cloud gateways, and wireless access points (versions R0162P07, UAP700-WPT330-E2265, UAP672-WPT330-R2262, UAP662E-WPT330-R2262P03, WAP611-WPT330-R1348-OASIS, WAP662-WPT330-R2…

πŸ“… Published: Nov. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346572
Page 2723 of 34,658
Β« previous page Β» next page
Filters