3.7

CVSS3.1

CVE-2025-51591 - pandoc: Server-Side Request Forgery in Pandoc

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilitie…

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-52994 -

gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-52089 -

A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands with root privileges.

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: July 19, 2025, 3:15 a.m.

4.1

CVSS3.1

CVE-2025-45582 - tar: Tar path traversal

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, speci…

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: Nov. 2, 2025, 1:15 a.m.

8.3

CVSS3.1

CVE-2013-3307 -

Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000.

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2023-38327 -

An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web applications based on server response.

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 8:50 p.m.

6.1

CVSS3.1

CVE-2023-38329 -

An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web script or HTML into the "user" HTTP/GET parameter, which reflects its input without saniti…

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 8:49 p.m.

5.8

CVSS3.1

CVE-2025-53864 - com.nimbusds/nimbus-jose-jwt: Uncontrolled recursion in Connect2id Nimbus JOSE + JWT

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id …

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-7519 - Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is …

πŸ“… Published: July 11, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

5.9

CVSS4.0

CVE-2025-53471 - Emerson ValveLink Products Improper Input Validation

Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

πŸ“… Published: July 10, 2025, 11:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345202
Page 4281 of 34,521
Β« previous page Β» next page
Filters