6.8

CVSS3.1

CVE-2025-7371 -

Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You…

πŸ“… Published: July 22, 2025, 3:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-8019 - Shenzhen Libituo Technology LBT-T300-T310 appy.cgi sub_40B6F0 buffer overflow

A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected by this issue is the function sub_40B6F0 of the file at/appy.cgi. The manipulation of the argument wan_proto leads to buffer overflow. The attack may be launched remotely. The exp…

πŸ“… Published: July 22, 2025, 3:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 8:14 p.m.

7.5

CVSS3.1

CVE-2025-36520 -

A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg Comdb2 8.1. A specially crafted network packets can lead to a denial of service. An attacker can send packets to trigger this vulnerability.

πŸ“… Published: July 22, 2025, 3:26 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

7.5

CVSS3.1

CVE-2025-46354 -

A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomberg Comdb2 8.1. A specially crafted network packet can lead to a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

πŸ“… Published: July 22, 2025, 3:26 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

7.5

CVSS3.1

CVE-2025-48498 -

A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when processing a number of fields used for coordination. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instan…

πŸ“… Published: July 22, 2025, 3:26 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

7.5

CVSS3.1

CVE-2025-36512 -

A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction heartbeat. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message t…

πŸ“… Published: July 22, 2025, 3:26 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

7.5

CVSS3.1

CVE-2025-35966 -

A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2 8.1. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to t…

πŸ“… Published: July 22, 2025, 3:26 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

6.4

CVSS3.1

CVE-2025-8015 - Shortcodes Ultimate <= 7.4.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title …

The WP Shortcodes Plugin β€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded image's 'Title' and 'Slide link' fields in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for…

πŸ“… Published: July 22, 2025, 2:43 p.m. πŸ”„ Last Modified: April 20, 2026, 8:15 p.m.

5.3

CVSS4.0

CVE-2025-8018 - code-projects Food Ordering Review System reservation_page.php sql injection

A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user/reservation_page.php. The manipulation of the argument reg_Id leads to sql injection. The attack can be launched…

πŸ“… Published: July 22, 2025, 2:32 p.m. πŸ”„ Last Modified: July 29, 2025, 9:02 p.m.

4.6

CVSS3.1

CVE-2025-4295 - Host Header Injection in HotelRunner's B2B

Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting.This issue affects B2B: before 04.06.2025.

πŸ“… Published: July 22, 2025, 1:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346226
Page 4254 of 34,623
Β« previous page Β» next page
Filters