9.8

CVSS3.1

CVE-2025-43984 -

An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable to unauthenticated /goform/goform_set_cmd_process requests. A crafted POST request, using the SSID parameter, allows remote attackers to execute arb…

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2023-43683 -

An issue was discovered in Malwarebytes 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). A Stack buffer out-of-bounds access exists because of an integer underflow when handling newline characters.

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-53945 -

The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploita…

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2023-43692 -

An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). Out-of-bound reads in strings detection utilities lead to system crashes.

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-27846 -

In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOS are unprotected.

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2025-54409 - AIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (loca…

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a k…

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-55198 - Helm May Panic Due To Incorrect YAML Content

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring YAML files are formatted as Helm expects …

πŸ“… Published: Aug. 13, 2025, 11:23 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 9:28 p.m.

6.5

CVSS3.1

CVE-2025-55199 - Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been resolved in Helm 3.18.5. A workaround involves ens…

πŸ“… Published: Aug. 13, 2025, 11:23 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 9:25 p.m.

6.6

CVSS4.0

CVE-2025-55197 - pypdf's Manipulated FlateDecode streams can exhaust RAM

pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malicious cross-reference stream. Other content streams are affect…

πŸ“… Published: Aug. 13, 2025, 11:03 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 8:05 p.m.

7.1

CVSS4.0

CVE-2025-55196 - External Secrets Operator Missing Namespace Restriction in PushSecret and SecretStore List() Calls …

External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15.0 to before 0.19.2, a vulnerability was discovered where the List() calls for Kubernetes Secret and SecretStore resources performed by the PushSecret controller did not apply a n…

πŸ“… Published: Aug. 13, 2025, 10:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348208
Page 4199 of 34,821
Β« previous page Β» next page
Filters