7.5

CVSS3.1

CVE-2025-57889 - WordPress InPost Gallery Plugin <= 2.1.4.5 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 InPost Gallery inpost-gallery allows PHP Local File Inclusion.This issue affects InPost Gallery: from n/a through <= 2.1.4.5.

๐Ÿ“… Published: Sept. 5, 2025, 4:15 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.8

CVSS3.1

CVE-2025-32320 -

In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 5, 2025, 4:10 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

8.8

CVSS3.1

CVE-2025-32318 -

In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 5, 2025, 4:10 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

5.5

CVSS3.1

CVE-2025-32317 -

In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 5, 2025, 4:10 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 4:39 p.m.

5.5

CVSS3.1

CVE-2025-32316 -

In gralloc4, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 5, 2025, 4:10 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 4:38 p.m.

3.3

CVSS3.1

CVE-2025-26461 -

In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the user attempts to close the app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction iโ€ฆ

๐Ÿ“… Published: Sept. 5, 2025, 4:10 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 4:38 p.m.

5.5

CVSS3.1

CVE-2025-26434 - libxml2: Libxml2 out of bounds read

In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 5, 2025, 4:10 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 4:38 p.m.

5.5

CVSS3.1

CVE-2024-0028 -

In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: Sept. 5, 2025, 4:10 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 4:38 p.m.

5.3

CVSS4.0

CVE-2025-10013 - Portabilis i-Educar exportacao-para-o-seb access control

A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao-para-o-seb. Performing manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit is now public and may be used.

๐Ÿ“… Published: Sept. 5, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 2:25 p.m.

5.3

CVSS4.0

CVE-2025-10012 - Portabilis i-Educar educar_historico_escolar_lst.php sql injection

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation of the argument ref_cod_aluno leads to sql injection. The attack can be executed remotely. The exploit has been dโ€ฆ

๐Ÿ“… Published: Sept. 5, 2025, 2:32 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 2:24 p.m.
Total resulsts: 349182
Page 3980 of 34,919
ยซ previous page ยป next page
Filters