6.9

CVSS4.0

CVE-2025-8396 -

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, …

πŸ“… Published: Sept. 15, 2025, 2:13 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2023-53171 - vfio/type1: prevent underflow of locked_vm via exec()

In the Linux kernel, the following vulnerability has been resolved: vfio/type1: prevent underflow of locked_vm via exec() When a vfio container is preserved across exec, the task does not change, but it gets a new mm with locked_vm=0, and loses the count from existing dma mappings. If the user l…

πŸ“… Published: Sept. 15, 2025, 2:04 p.m. πŸ”„ Last Modified: Dec. 2, 2025, 2:58 a.m.

6.9

CVSS4.0

CVE-2025-10448 - Campcodes Online Job Finder System index.php sql injection

A flaw has been found in Campcodes Online Job Finder System 1.0. This affects an unknown function of the file /index.php?q=result&searchfor=bycompany. This manipulation of the argument Search causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

πŸ“… Published: Sept. 15, 2025, 2:02 p.m. πŸ”„ Last Modified: Sept. 20, 2025, 2:52 a.m.

7.8

CVSS3.1

CVE-2022-50243 - sctp: handle the error returned from sctp_auth_asoc_init_active_key

In the Linux kernel, the following vulnerability has been resolved: sctp: handle the error returned from sctp_auth_asoc_init_active_key When it returns an error from sctp_auth_asoc_init_active_key(), the active_key is actually not updated. The old sh_key will be freeed while it's still used as ac…

πŸ“… Published: Sept. 15, 2025, 2:01 p.m. πŸ”„ Last Modified: Nov. 24, 2025, 8:04 p.m.

6.9

CVSS4.0

CVE-2025-10447 - Campcodes Online Job Finder System applicationform.php unrestricted upload

A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of the file /eris/applicationform.php. The manipulation of the argument picture results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public…

πŸ“… Published: Sept. 15, 2025, 1:32 p.m. πŸ”„ Last Modified: Sept. 20, 2025, 2:52 a.m.

6.9

CVSS4.0

CVE-2025-10446 - Campcodes Computer Sales and Inventory System cust_searchfrm.php sql injection

A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_searchfrm.php?action=edit. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely.…

πŸ“… Published: Sept. 15, 2025, 1:02 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 7:26 p.m.

6.9

CVSS4.0

CVE-2025-10445 - Campcodes Computer Sales and Inventory System us_transac.php sql injection

A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/us_transac.php?action=add. Executing manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been…

πŸ“… Published: Sept. 15, 2025, 12:32 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 7:26 p.m.

7.3

CVSS3.1

CVE-2025-3025 - CCleaner Link Following Local Privilege Escalation Vulnerability

Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local user to gain SYSTEM privileges via exploiting insecure file delete operations. Reported in CCleaner v. 6.33.11465. This issue affects CCleaner: before < 6.36.11508.

πŸ“… Published: Sept. 15, 2025, 12:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10444 - Campcodes Online Job Finder System advancesearch.php sql injection

A security flaw has been discovered in Campcodes Online Job Finder System 1.0. This issue affects some unknown processing of the file /advancesearch.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has bee…

πŸ“… Published: Sept. 15, 2025, 12:02 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 7:25 p.m.

9.8

CVSS3.1

CVE-2025-59361 - OS command injection in Chaos Mesh via the cleanIptables mutation

The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.

πŸ“… Published: Sept. 15, 2025, 11:41 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 2:43 p.m.
Total resulsts: 349182
Page 3856 of 34,919
Β« previous page Β» next page
Filters