5.5

CVSS4.0

CVE-2025-55207 - @astrojs/node's trailing slash handling causes open redirect issue

Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios prior to version 9.4.1. Astro 5.12.8 addressed CVE-2025-54793 where https://example.com//astro.build/press would redirect to the exte…

📅 Published: Aug. 15, 2025, 3:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-24975 - Firebird Non-Authorized Access to Encrypted Database Using Execute Statement on External

Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not set equal to 0. If connections stored in ExtConnPool are not verified for presence and suitability of the CryptCallback interface is used when create…

📅 Published: Aug. 15, 2025, 3:11 p.m. 🔄 Last Modified: Oct. 9, 2025, 7:04 p.m.

5.4

CVSS3.1

CVE-2025-55203 - Plane Stored XSS in Add Work Item Functionality

Plane is open-source project management software. Prior to version 0.28.0, a stored cross-site scripting (XSS) vulnerability exists in the description_html field of Plane. This flaw allows an attacker to inject malicious JavaScript code that is stored and later executed in other users’ browsers. Th…

📅 Published: Aug. 15, 2025, 3:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-54989 - Firebird XDR Message Parsing NULL Pointer Dereference Denial-of-Service Vulnerability

Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. It leads to NULL pointer dereference and DoS.…

📅 Published: Aug. 15, 2025, 3:04 p.m. 🔄 Last Modified: Nov. 3, 2025, 7:16 p.m.

7.8

CVSS3.1

CVE-2025-5048 - DGN File Parsing Memory Corruption Vulnerability

A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

📅 Published: Aug. 15, 2025, 2:38 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:48 p.m.

7.8

CVSS3.1

CVE-2025-5047 - DGN File Parsing Uninitialized Variable Vulnerability

A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

📅 Published: Aug. 15, 2025, 2:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:48 p.m.

7.8

CVSS3.1

CVE-2025-5046 - DGN File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

📅 Published: Aug. 15, 2025, 2:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:48 p.m.

6.3

CVSS3.1

CVE-2025-54466 - Apache OFBiz: RCE Vulnerability in scrum plugin

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are recommend…

📅 Published: Aug. 15, 2025, 2:13 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:48 p.m.

6.9

CVSS4.0

CVE-2025-9053 - projectworlds Travel Management System updatesubcategory.php sql injection

A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /updatesubcategory.php. The manipulation of the argument t1/s1 leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public…

📅 Published: Aug. 15, 2025, 1:02 p.m. 🔄 Last Modified: Aug. 21, 2025, 6:58 p.m.

6.9

CVSS4.0

CVE-2025-9052 - projectworlds Travel Management System updatepackage.php sql injection

A vulnerability was identified in projectworlds Travel Management System 1.0. This affects an unknown part of the file /updatepackage.php. The manipulation of the argument s1 leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…

📅 Published: Aug. 15, 2025, 12:32 p.m. 🔄 Last Modified: Aug. 21, 2025, 7:04 p.m.
Total resulsts: 349182
Page 4258 of 34,919
« previous page » next page
Filters