9.8

CVSS3.1

CVE-2025-50870 -

Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The myds GET parameter accepts an email address as input and directly returns the corresponding student's personal information without validating the identity or permissions of the requ…

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-50460 -

A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py using yaml.load() from the PyYAML library (versions = 5.3.1). If an attacker can control the content of the YAML configuration file passed to the --run_config param…

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-51501 -

Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: Aug. 19, 2025, 3:36 p.m.

9.8

CVSS3.1

CVE-2025-50472 -

The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_model_meta()` function of the `ModelFileSystemCache()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized `.mdl` p…

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2019-19144 -

XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?action=authenticate.

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.2

CVSS3.1

CVE-2023-44976 -

Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E010, as exploited in the wild in October 2023.

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-52390 -

Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without sanitization, allowi…

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-46018 -

CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and potential financial loss.

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 1:36 p.m.

6.1

CVSS3.1

CVE-2025-45778 -

A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description text field.

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 4:15 p.m.

5.3

CVSS3.1

CVE-2025-54939 -

LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

πŸ“… Published: Aug. 1, 2025, midnight πŸ”„ Last Modified: Aug. 27, 2025, 3:52 p.m.
Total resulsts: 346939
Page 4218 of 34,694
Β« previous page Β» next page
Filters