9.8

CVSS3.1

CVE-2025-61455 -

SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorporates unsanitized user inputs into SQL queries, allowing unauthenticated attackers to bypass authentication and gain full access.

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 10:24 a.m.

7.5

CVSS3.1

CVE-2025-61301 -

Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submit samples to cause incomplete or missing behavioral analysis reports by generating deeply nested or oversized behavior data that trigger MongoDB BSON limits o…

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Oct. 29, 2025, 11:33 a.m.

9.8

CVSS3.1

CVE-2025-61303 -

Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a submitted malware sample to evade detection and cause denial-of-analysis. The vulnerability is triggered when a sample rec…

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 10:24 a.m.

6.1

CVSS3.1

CVE-2025-60781 -

PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_name parameter.

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Oct. 22, 2025, 4:52 p.m.

6.5

CVSS3.1

CVE-2025-60783 -

There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipulate the application's database through specially crafted SQL query strings.

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 3:14 p.m.

5.5

CVSS3.1

CVE-2025-40008 - kmsan: fix out-of-bounds access to shadow memory

In the Linux kernel, the following vulnerability has been resolved: kmsan: fix out-of-bounds access to shadow memory Running sha224_kunit on a KMSAN-enabled kernel results in a crash in kmsan_internal_set_shadow_origin(): BUG: unable to handle page fault for address: ffffbc3840291000 #PF…

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

6.1

CVSS3.1

CVE-2025-61456 -

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoint. Unsanitized input in the /index parameter is directly reflected back into the response HTML, allowing attackers to execute arbitrary JavaScript in the browser of a user who vis…

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 10:24 a.m.

5.5

CVSS3.1

CVE-2025-40004 - net/9p: Fix buffer overflow in USB transport layer

In the Linux kernel, the following vulnerability has been resolved: net/9p: Fix buffer overflow in USB transport layer A buffer overflow vulnerability exists in the USB 9pfs transport layer where inconsistent size validation between packet header parsing and actual data copying allows a malicious…

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.5

CVSS3.1

CVE-2024-55568 -

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a Denial of Service when an attacker sends malfo…

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 1:11 p.m.

7.5

CVSS3.1

CVE-2025-56223 -

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.

πŸ“… Published: Oct. 20, 2025, midnight πŸ”„ Last Modified: Oct. 27, 2025, 1:52 p.m.
Total resulsts: 343926
Page 2844 of 34,393
Β« previous page Β» next page
Filters