9.3

CVSS4.0

CVE-2025-34099 - VICIdial vicidial_sales_viewer.php Unauthenticated Command Injection via Basic Auth Password

An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vicidial_sales_viewer.php component when password encryption is enabled (a non-default configuration). The application improperly passes the HTTP Basic Authentication password directl…

πŸ“… Published: July 10, 2025, 7:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7021 - OpenAI Operator - API Spoofing through Locking Operator on FullScreen

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email addresses) via displaying a deceptive fullscreen interface with overlaid fake browser …

πŸ“… Published: July 10, 2025, 7:09 p.m. πŸ”„ Last Modified: July 24, 2025, 7:13 p.m.

7.5

CVSS3.1

CVE-2025-52520 - Apache Tomcat: DoS via integer overflow in multipart file upload

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following v…

πŸ“… Published: July 10, 2025, 7:05 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2025-52434 - Apache Tomcat: APR/Native Connector crash leading to DoS

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 throu…

πŸ“… Published: July 10, 2025, 7:03 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.9

CVSS4.0

CVE-2025-7411 - code-projects LifeStyle Store success.php sql injection

A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /success.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has bee…

πŸ“… Published: July 10, 2025, 7:02 p.m. πŸ”„ Last Modified: July 16, 2025, 3:02 p.m.

7.8

CVSS3.1

CVE-2025-53503 -

Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

πŸ“… Published: July 10, 2025, 6:59 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:44 a.m.

7.6

CVSS3.1

CVE-2025-53378 -

A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS o…

πŸ“… Published: July 10, 2025, 6:58 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:46 a.m.

7.8

CVSS3.1

CVE-2025-52837 -

Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any file/folder and achieve privilege escalation.

πŸ“… Published: July 10, 2025, 6:57 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.8

CVSS3.1

CVE-2025-52521 -

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

πŸ“… Published: July 10, 2025, 6:57 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.1

CVSS3.1

CVE-2025-53626 - pdfme has Sandbox Escape and Prototype Pollution vulnerabilities in pdfme expression evaluation

pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.

πŸ“… Published: July 10, 2025, 6:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345171
Page 4284 of 34,518
Β« previous page Β» next page
Filters