8.1

CVSS3.1

CVE-2025-9185 - Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefoxโ€ฆ

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploโ€ฆ

๐Ÿ“… Published: Aug. 19, 2025, 8:33 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 6:15 p.m.

6.5

CVSS3.1

CVE-2025-9181 - Uninitialized memory in the JavaScript Engine component

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.

๐Ÿ“… Published: Aug. 19, 2025, 8:33 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 6:15 p.m.

8.1

CVSS3.1

CVE-2025-9180 - Same-origin policy bypass in the Graphics: Canvas2D component

Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.

๐Ÿ“… Published: Aug. 19, 2025, 8:33 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 6:15 p.m.

9.8

CVSS3.1

CVE-2025-9179 - Sandbox escape due to invalid pointer in the Audio/Video: GMP component

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Fโ€ฆ

๐Ÿ“… Published: Aug. 19, 2025, 8:33 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 5 p.m.

5.1

CVSS4.0

CVE-2025-9167 - SolidInvoice Recurring Invoice recurring cross site scripting

A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. The manipulation of the argument client name leads to cross site scripting. The attack may be initiated remotely. The exploitโ€ฆ

๐Ÿ“… Published: Aug. 19, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 6:38 p.m.

2

CVSS4.0

CVE-2025-9165 - LibTIFF tiffcmp tiffcmp.c InitCCITTFax3 memory leak

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterโ€ฆ

๐Ÿ“… Published: Aug. 19, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: Oct. 1, 2025, 4:15 p.m.

4.8

CVSS4.0

CVE-2025-9157 - appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free

A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. Executing manipulation can lead to use after free. It is possible to launch the attack on the local host. Theโ€ฆ

๐Ÿ“… Published: Aug. 19, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-55740 - Default Credentials in nginx-defender Configuration Files

nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files config.yaml and docker-compose.yml contโ€ฆ

๐Ÿ“… Published: Aug. 19, 2025, 7:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-43744 -

A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 andโ€ฆ

๐Ÿ“… Published: Aug. 19, 2025, 7:34 p.m. ๐Ÿ”„ Last Modified: Dec. 15, 2025, 8:05 p.m.

6.9

CVSS4.0

CVE-2025-9156 - itsourcecode Sports Management System sports.php sql injection

A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public aโ€ฆ

๐Ÿ“… Published: Aug. 19, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 6:40 p.m.
Total resulsts: 349182
Page 4221 of 34,919
ยซ previous page ยป next page
Filters