7.8

CVSS3.1

CVE-2025-43268 - macOS Permissions Issue Enabling Root Privilege Escalation

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root privileges.

📅 Published: Aug. 29, 2025, 12:28 a.m. 🔄 Last Modified: April 28, 2026, 12:30 a.m.

3.3

CVSS3.1

CVE-2025-43255 - Out‑of‑Bounds Read Leading to Unexpected System Termination in macOS

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

📅 Published: Aug. 29, 2025, 12:28 a.m. 🔄 Last Modified: April 28, 2026, 11 a.m.

7.3

CVSS3.1

CVE-2025-40927 - CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flaw

CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for reflected XSS or open redirect under certain conditions. Although some valid…

📅 Published: Aug. 29, 2025, 12:10 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-9598 - itsourcecode Apartment Management System year_setup.php sql injection

A security flaw has been discovered in itsourcecode Apartment Management System 1.0. Affected is an unknown function of the file /setting/year_setup.php. Performing manipulation of the argument txtXYear results in sql injection. The attack can be initiated remotely. The exploit has been released to…

📅 Published: Aug. 29, 2025, 12:02 a.m. 🔄 Last Modified: Sept. 2, 2025, 5:01 p.m.

6.9

CVSS4.0

CVE-2025-9597 - itsourcecode Apartment Management System rented_all_info.php sql injection

A vulnerability was identified in itsourcecode Apartment Management System 1.0. This impacts an unknown function of the file /o_dashboard/rented_all_info.php. Such manipulation of the argument uid leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly availabl…

📅 Published: Aug. 29, 2025, 12:02 a.m. 🔄 Last Modified: Sept. 2, 2025, 5:33 p.m.

7.8

CVSS3.1

CVE-2023-41471 -

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors who already have write access to the server, and they can mor…

📅 Published: Aug. 29, 2025, midnight 🔄 Last Modified: Nov. 3, 2025, 6:15 a.m.

8.1

CVSS3.1

CVE-2024-46916 -

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remove the /etc/fstab file). This can allow code execution and, …

📅 Published: Aug. 29, 2025, midnight 🔄 Last Modified: Sept. 9, 2025, 2:09 p.m.

8.1

CVSS3.1

CVE-2024-46917 -

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recovery of TPM Disk Encryption keys, decryption of the Windows system partition, and full control of the Windows OS, e.g., t…

📅 Published: Aug. 29, 2025, midnight 🔄 Last Modified: Sept. 9, 2025, 2:02 p.m.

5.4

CVSS3.1

CVE-2025-55579 -

SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.

📅 Published: Aug. 29, 2025, midnight 🔄 Last Modified: Sept. 9, 2025, 2 p.m.

9.8

CVSS3.1

CVE-2024-46484 -

TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.

📅 Published: Aug. 29, 2025, midnight 🔄 Last Modified: Sept. 8, 2025, 4:42 p.m.
Total resulsts: 349182
Page 4094 of 34,919
« previous page » next page
Filters