6.1

CVSS3.1

CVE-2025-52277 -

Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 8:26 p.m.

7.5

CVSS3.1

CVE-2025-57058 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel, and pModule parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 15, 2025, 6:14 p.m.

5.4

CVSS3.1

CVE-2025-57539 -

A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to store malicious input. The payload is rendered unsafely in the Web UI and executed when viewed by other users, potentially…

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 18, 2025, 5:41 p.m.

7.5

CVSS3.1

CVE-2025-57086 -

Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 7:49 p.m.

7.5

CVSS3.1

CVE-2025-57069 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 18, 2025, 6:49 p.m.

7.5

CVSS3.1

CVE-2025-57078 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the formModifyPppAuthWhiteMac function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 8 p.m.

7.5

CVSS3.1

CVE-2025-57060 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_store function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 7:38 p.m.

8.8

CVSS3.1

CVE-2025-58757 - MONAI's unsafe use of Pickle deserialization may lead to RCE

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in `monai/data/utils.py` automatically handles dictionary key-value pairs ending with a specific suffix and deserializes them using `pickle.loads()` …

πŸ“… Published: Sept. 8, 2025, 11:42 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:26 p.m.

8.8

CVSS3.1

CVE-2025-58756 - MONAI's unsafe torch usage may lead to arbitrary code execution

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)` in monai/bundle/scripts.py , `weights_only=True` is loaded securely. However, insecure l…

πŸ“… Published: Sept. 8, 2025, 11:39 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:26 p.m.

8.8

CVSS3.1

CVE-2025-58755 - MONAI has path traversal issue that may lead to arbitrary file writes

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to process compressed files. It is used in many places in the project. In versions up to and including 1.5.0, when the Zip file containing malicio…

πŸ“… Published: Sept. 8, 2025, 11:35 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:25 p.m.
Total resulsts: 349182
Page 3958 of 34,919
Β« previous page Β» next page
Filters