7.8

CVSS3.1

CVE-2025-20706 -

In mbrain, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924624; Issue ID: MSV-3826.

πŸ“… Published: Sept. 1, 2025, 5:12 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

7.8

CVSS3.1

CVE-2025-20705 -

In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09989078; Issue ID: MSV-3964.

πŸ“… Published: Sept. 1, 2025, 5:12 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

8

CVSS3.1

CVE-2025-20704 -

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. …

πŸ“… Published: Sept. 1, 2025, 5:12 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

6.5

CVSS3.1

CVE-2025-20703 -

In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. …

πŸ“… Published: Sept. 1, 2025, 5:12 a.m. πŸ”„ Last Modified: Feb. 17, 2026, 3:16 p.m.

8.8

CVSS3.1

CVE-2025-20708 -

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploit…

πŸ“… Published: Sept. 1, 2025, 5:12 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

9.8

CVSS3.0

CVE-2025-6507 - Deserialization of Untrusted Data in h2oai/h2o-3

A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code execution and reading of system files. This issue affects the latest master branch version 3.47.0.99999. The vulnerability arises from the ability to by…

πŸ“… Published: Sept. 1, 2025, 5:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-9763 - Campcodes Online Learning Management System student_signup.php sql injection

A vulnerability was detected in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /student_signup.php. The manipulation of the argument Username results in sql injection. The attack can be launched remotely. The exploit is now public and may be …

πŸ“… Published: Sept. 1, 2025, 5:02 a.m. πŸ”„ Last Modified: Sept. 8, 2025, 1:40 p.m.

6.9

CVSS4.0

CVE-2025-9761 - Campcodes Online Feeds Product Inventory System Login index.php sql injection

A security vulnerability has been detected in Campcodes Online Feeds Product Inventory System 1.0. This vulnerability affects unknown code of the file /feeds/index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The…

πŸ“… Published: Sept. 1, 2025, 4:32 a.m. πŸ”„ Last Modified: Sept. 8, 2025, 1:45 p.m.

5.3

CVSS4.0

CVE-2025-9760 - Portabilis i-Educar Matricula API matricula improper authorization

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Matricula API. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made availab…

πŸ“… Published: Sept. 1, 2025, 4:02 a.m. πŸ”„ Last Modified: Sept. 27, 2025, 12:28 a.m.

7.5

CVSS3.1

CVE-2025-7731 - Information Disclosure Vulnerability in MELSEC iQ-F Series CPU module

Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain credential information by intercepting SLMP communication messages, and read or write the device values of the product an…

πŸ“… Published: Sept. 1, 2025, 3:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4068 of 34,919
Β« previous page Β» next page
Filters