7.4

CVSS3.1

CVE-2025-36244 - IBM AIX privilege escalation

IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.

πŸ“… Published: Sept. 16, 2025, 2:38 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

9.3

CVSS4.0

CVE-2009-20007 - Talkative IRC v0.4.4.16 Response Buffer Overflow

Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when processing specially crafted response strings sent to a connected client. An attacker can exploit this flaw by sending an overly long message that overflows a fixed-length buffer, potentially leading to arbitrary code execu…

πŸ“… Published: Sept. 16, 2025, 2:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2009-20006 - osCommerce <= 2.2 Admin File Manager Arbitrary PHP Code Execution

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to up…

πŸ“… Published: Sept. 16, 2025, 2:33 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2009-20005 - InterSystems CachΓ© UtilConfigHome.csp Stack Buffer Overflow

A stack-based buffer overflow exists in the UtilConfigHome.csp endpoint of InterSystems CachΓ© 2009.1. The vulnerability is triggered by sending a specially crafted HTTP GET request containing an oversized argument to the .csp handler. Due to insufficient bounds checking, the input overflows a stack…

πŸ“… Published: Sept. 16, 2025, 2:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-13174 - SQLi in E1 Informatics' Web Application

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E1 Informatics Web Application allows SQL Injection.This issue affects Web Application: through 20250916.Β  NOTE: The vendor did not inform about the completion of the fixing process within the spe…

πŸ“… Published: Sept. 16, 2025, 2:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-8894 - PDF File Parsing Heap-Based Buffer Overflow Vulnerability

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Sept. 16, 2025, 2:19 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

8.1

CVSS3.1

CVE-2025-59333 - @executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode

The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impa…

πŸ“… Published: Sept. 16, 2025, 2:18 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:18 p.m.

7.8

CVSS3.1

CVE-2025-8893 - PDF File Parsing Out-of-Bounds Write Vulnerability

A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

πŸ“… Published: Sept. 16, 2025, 2:17 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

9.8

CVSS3.1

CVE-2024-13149 - SQLi in Arma Store's Armalife

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arma Store Armalife allows SQL Injection.This issue affects Armalife: through 20250916.Β  NOTE: The vendor did not inform abo…

πŸ“… Published: Sept. 16, 2025, 2:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-8057 - IDOR in Patika Global Technologies' HumanSuite

Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Improper Authorization vulnerability in Patika Global Technologies HumanSuite allows Exploiting Trust in Client.This issue affects HumanSuite: before 53.21.0.

πŸ“… Published: Sept. 16, 2025, 2:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3823 of 34,919
Β« previous page Β» next page
Filters