9.8

CVSS3.1

CVE-2025-0074 -

In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Aug. 26, 2025, 10:48 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:08 p.m.

5.5

CVSS3.1

CVE-2024-49740 -

In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Aug. 26, 2025, 10:48 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:08 p.m.

8

CVSS3.1

CVE-2023-21125 -

In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Aug. 26, 2025, 10:48 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:08 p.m.

7.9

CVSS4.0

CVE-2025-57820 - Svelte devalue vulnerable to prototype pollution

Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse does not check that an index is numeric. This could result in assigning prototypes to objects and properties, leading to prototype poll…

πŸ“… Published: Aug. 26, 2025, 10:33 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-9277 - SiteSEO – SEO Simplified <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Br…

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_replace expression in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Cont…

πŸ“… Published: Aug. 26, 2025, 10:26 p.m. πŸ”„ Last Modified: April 20, 2026, 8 p.m.

5.1

CVSS4.0

CVE-2025-35112 - Agiloft XML external entity local path traversal

Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31.

πŸ“… Published: Aug. 26, 2025, 10:19 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:59 p.m.

9.2

CVSS4.0

CVE-2025-35115 - Agiloft insecure download of system packages

Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the contents of the download URL. Users should upgrade to Agiloft Release 30.

πŸ“… Published: Aug. 26, 2025, 10:18 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:57 p.m.

8.7

CVSS4.0

CVE-2025-35114 - Agiloft local privilege escalation via default credentials

Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30.

πŸ“… Published: Aug. 26, 2025, 10:18 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:58 p.m.

4.8

CVSS4.0

CVE-2025-35113 - Agiloft improper neutralization in EUI template engine

Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Release 31.

πŸ“… Published: Aug. 26, 2025, 10:17 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:58 p.m.

6.9

CVSS4.0

CVE-2025-9492 - Campcodes Online Water Billing System addclient1.php sql injection

A vulnerability was determined in Campcodes Online Water Billing System 1.0. This affects an unknown function of the file /addclient1.php. Executing manipulation of the argument lname can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be …

πŸ“… Published: Aug. 26, 2025, 10:02 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:09 p.m.
Total resulsts: 349182
Page 4132 of 34,919
Β« previous page Β» next page
Filters