9.6

CVSS3.1

CVE-2025-60739 -

Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component

πŸ“… Published: Nov. 25, 2025, midnight πŸ”„ Last Modified: Dec. 30, 2025, 5:04 p.m.

7.2

CVSS3.1

CVE-2025-64050 -

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. The payload is executed when visitors access frontend pages …

πŸ“… Published: Nov. 25, 2025, midnight πŸ”„ Last Modified: Dec. 3, 2025, 5:06 p.m.

8.5

CVSS3.1

CVE-2025-62155 - QuantumNous New API Has SSRF Bypass

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulnerability contains a bypass method that can bypass the existing security fix and still allow SSRF to occur. Because the existing fix only appl…

πŸ“… Published: Nov. 24, 2025, 11:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-65018 - LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish…

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_read when processing …

πŸ“… Published: Nov. 24, 2025, 11:50 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 6:34 p.m.

7.1

CVSS3.1

CVE-2025-64720 - LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premu…

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMI…

πŸ“… Published: Nov. 24, 2025, 11:45 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 6:35 p.m.

6.1

CVSS3.1

CVE-2025-64506 - LIBPNG is vulnerable to a heap buffer over-read in `png_write_image_8bit` with grayscale+alpha or R…

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_write_image_8bit function when processing 8-bit images throug…

πŸ“… Published: Nov. 24, 2025, 11:41 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 6:34 p.m.

6.1

CVSS3.1

CVE-2025-64505 - LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, a heap buffer over-read vulnerability exists in libpng's png_do_quantize function when processing PNG files with malformed palette ind…

πŸ“… Published: Nov. 24, 2025, 11:38 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 6:28 p.m.

6.5

CVSS3.1

CVE-2025-10144 - Perfect Brands for WooCommerce <= 3.6.2 - Authenticated (Contributor+) SQL Injection

The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortcode in all versions up to, and including, 3.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the …

πŸ“… Published: Nov. 24, 2025, 10:28 p.m. πŸ”„ Last Modified: April 22, 2026, 12:30 a.m.

5.5

CVSS3.1

CVE-2025-29933 -

Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service

πŸ“… Published: Nov. 24, 2025, 9:03 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 6:49 p.m.

5.5

CVSS3.1

CVE-2025-48511 -

Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of service.

πŸ“… Published: Nov. 24, 2025, 9 p.m. πŸ”„ Last Modified: Nov. 26, 2025, 6:45 p.m.
Total resulsts: 349182
Page 2914 of 34,919
Β« previous page Β» next page
Filters