7.7

CVSS4.0

CVE-2025-5115 - MadeYouReset HTTP/2 vulnerability

In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume…

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Jan. 27, 2026, 7:23 p.m.

7.5

CVSS3.1

CVE-2024-53495 -

Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 7:12 p.m.

6.5

CVSS3.1

CVE-2025-55499 -

Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 6:22 p.m.

8.8

CVSS3.1

CVE-2025-50503 -

A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without needing to provide a …

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-28041 -

Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 2:07 p.m.

6.9

CVSS4.0

CVE-2025-57788 - Unauthorized API Access Risk

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.

πŸ“… Published: Aug. 20, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 2:02 p.m.

4.8

CVSS4.0

CVE-2025-9176 - neurobin shc Environment Variable shc.c make os command injection

A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Variable Handler. The manipulation results in os command injection. The attack is only possible with local access. The exploit has been released to the p…

πŸ“… Published: Aug. 19, 2025, 11:32 p.m. πŸ”„ Last Modified: Sept. 12, 2025, 2:06 p.m.

4.8

CVSS4.0

CVE-2025-9175 - neurobin shc shc.c make stack-based overflow

A vulnerability was identified in neurobin shc up to 4.0.3. This issue affects the function make of the file src/shc.c. The manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used.

πŸ“… Published: Aug. 19, 2025, 11:02 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 7:19 p.m.

4.8

CVSS4.0

CVE-2025-9174 - neurobin shc Filename shc.c make os command injection

A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filename Handler. Executing manipulation can lead to os command injection. The attack can only be executed locally. The exploit has been publicly disclosed…

πŸ“… Published: Aug. 19, 2025, 10:32 p.m. πŸ”„ Last Modified: Sept. 15, 2025, 7:54 p.m.

5.1

CVSS4.0

CVE-2025-9171 - SolidInvoice Clients clients cross site scripting

A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attack is possible to be carried out remotely. The exp…

πŸ“… Published: Aug. 19, 2025, 10:32 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 6:27 p.m.
Total resulsts: 349182
Page 4218 of 34,919
Β« previous page Β» next page
Filters