6.9

CVSS4.0

CVE-2022-50687 - Cobian Backup 11 Gravity 11.2.0.582 Local Denial of Service via Password Field

Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generate a specially crafted 800-byte buffer and paste it into the password field to trigger an application crash.

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

6.9

CVSS4.0

CVE-2021-47715 - Hasura GraphQL 1.3.3 Server-Side Request Forgery via Remote Schema Injection

Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL defini…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

6.9

CVSS4.0

CVE-2021-47714 - Hasura GraphQL 1.3.3 Local File Read via SQL Injection

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

8.7

CVSS4.0

CVE-2021-47713 - Hasura GraphQL 1.3.3 Denial of Service via Malicious GraphQL Query

Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources …

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

8.2

CVSS4.0

CVE-2025-68476 - KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Cr…

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerabilit…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

7.5

CVSS3.1

CVE-2025-68475 - Fedify has ReDoS Vulnerability in HTML Parsing Regex

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/doclo…

πŸ“… Published: Dec. 22, 2025, 9:31 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:31 p.m.

8.7

CVSS4.0

CVE-2025-34457 - wb2osz/direwolf <= 1.8 Stack-based Buffer Overflow DoS

wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 694c954, contain a stack-based buffer overflow vulnerability in the function kiss_rec_byte() located in src/kiss_frame.c. When processing crafted KISS frames that reach the maximum allowed frame length (MAX_KISS_LEN), the…

πŸ“… Published: Dec. 22, 2025, 9:30 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:30 p.m.

8.7

CVSS4.0

CVE-2025-34458 - wb2osz/direwolf <= 1.8 Reachable Assertion DoS

wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e() located in src/decode_aprs.c. When processing a specially crafted AX.25 frame containing a MIC-E message with an empty o…

πŸ“… Published: Dec. 22, 2025, 9:29 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:29 p.m.

5.3

CVSS3.1

CVE-2025-68480 - Marshmallow has DoS in Schema.load(many)

Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a dispr…

πŸ“… Published: Dec. 22, 2025, 9:20 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:20 p.m.

6.5

CVSS3.1

CVE-2025-15033 - WooCommerce - Subscriber/Customer+ Order Data Disclosure

A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it ha…

πŸ“… Published: Dec. 22, 2025, 6:57 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 11:56 p.m.
Total resulsts: 323671
Page 4 of 32,368
Β« previous page Β» next page
Filters