5.6

CVSS3.1

CVE-2025-40929 - Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault whe…

Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

📅 Published: Sept. 8, 2025, 3:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-40928 - JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsin…

JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

📅 Published: Sept. 8, 2025, 3:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7709 - Out Of Bounds write in FTS5 Extension in SQLite

An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.

📅 Published: Sept. 8, 2025, 2:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-36855 - EOL .NET 6.0 Runtime Remote Code Execution Vulnerability

A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as index…

📅 Published: Sept. 8, 2025, 1:57 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-36854 - EOL ASP.NET 6.0 Remote Code Execution Vulnerability

A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution. Per CWE-416: Use After Free https://cwe.m…

📅 Published: Sept. 8, 2025, 1:53 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-36853 - EOL .NET 6.0 Runtime Remote Code Execution Vulnerability

A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning …

📅 Published: Sept. 8, 2025, 1:48 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-3212 - Mali GPU Kernel Driver allows access to already freed memory

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to gain access to already freed memory.This issue aff…

📅 Published: Sept. 8, 2025, 12:53 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

6.9

CVSS4.0

CVE-2025-10093 - D-Link DIR-852 Device Configuration getcfg.php phpcgi_main information disclosure

A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php of the component Device Configuration Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. The exploi…

📅 Published: Sept. 8, 2025, 12:02 p.m. 🔄 Last Modified: Sept. 29, 2025, 6:27 p.m.

5.1

CVSS4.0

CVE-2025-40641 - Stored Cross-Site Scripting (XSS) in the Multi-purpose Inventory Management System

Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request using the product_name parameter in /Controller_Products/update. This vulnerability could allow a remote …

📅 Published: Sept. 8, 2025, 11:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10092 - Jinher OA XML Type xml external entity reference

A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has…

📅 Published: Sept. 8, 2025, 11:32 a.m. 🔄 Last Modified: Oct. 9, 2025, 6:41 p.m.
Total resulsts: 349182
Page 3963 of 34,919
« previous page » next page
Filters