6.1

CVSS3.1

CVE-2025-51966 -

A cross-site scripting (XSS) vulnerability exists in the PDF preview functionality of uTools thru 7.1.1. When a user previews a specially crafted PDF file, embedded JavaScript code executes within the application's privileged context, potentially allowing attackers to steal sensitive data or perfor…

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 6:26 p.m.

7.5

CVSS3.1

CVE-2025-57614 -

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in the cached method allows an attacker to cause a denial of service or potentially execute arbitrary code. The vulnerability occurs when dimension parameters are zero or exceed i32::…

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 6:31 p.m.

7.5

CVSS3.1

CVE-2025-57612 -

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name() method allows an attacker to cause a denial of service. The vulnerability exists because the method fails to check for a NULL return value from the av_get_sample_fmt_name() C func…

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 6:35 p.m.

5.3

CVSS3.1

CVE-2025-55373 -

Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to escalate privileges and execute commands with Administrator rights.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 9:19 p.m.

7.5

CVSS3.1

CVE-2025-57616 -

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleaved method allows an attacker to cause a denial of service or memory corruption. The method violates Rust's aliasing rules by modifying a data structure through a mutable pointer w…

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 6:25 p.m.

6.5

CVSS3.1

CVE-2025-50755 -

Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 4, 2025, 5:47 p.m.

6.5

CVSS3.1

CVE-2025-50757 -

Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 4, 2025, 5:47 p.m.

6.5

CVSS3.1

CVE-2025-50565 -

Doubo ERP 1.0 has an SQL injection vulnerability due to a lack of filtering of user input, which can be remotely initiated by an attacker.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 6:51 p.m.

6.5

CVSS3.1

CVE-2025-32100 -

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. A programming mistake for buffer copy leads to out-of-bounds writes via mal…

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 7:09 p.m.

4.3

CVSS3.1

CVE-2025-56254 -

PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in leave-details.php. An authenticated user can change the leaveid parameter in the URL to access leave application details of other users.

πŸ“… Published: Sept. 2, 2025, midnight πŸ”„ Last Modified: Sept. 4, 2025, 5:02 p.m.
Total resulsts: 349182
Page 4059 of 34,919
Β« previous page Β» next page
Filters