6.9

CVSS4.0

CVE-2025-7410 - code-projects LifeStyle Store cart_remove.php sql injection

A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unknown function of the file /cart_remove.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed …

📅 Published: July 10, 2025, 5:02 p.m. 🔄 Last Modified: July 16, 2025, 3:02 p.m.

7.5

CVSS3.1

CVE-2025-53020 - Apache HTTP Server: HTTP/2 DoS by Memory Increase

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.

📅 Published: July 10, 2025, 4:59 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.4

CVSS3.1

CVE-2025-49812 - Apache HTTP Server: mod_ssl TLS upgrade attack

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommend…

📅 Published: July 10, 2025, 4:58 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2025-49630 - Apache HTTP Server: mod_proxy_http2 denial of service

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserv…

📅 Published: July 10, 2025, 4:57 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

9.1

CVSS3.1

CVE-2025-23048 - Apache HTTP Server: mod_ssl access control bypass with session resumption

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of tru…

📅 Published: July 10, 2025, 4:56 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:50 p.m.

7.5

CVSS3.1

CVE-2024-43394 - Apache HTTP Server: SSRF on Windows due to UNC paths

Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via  mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.63. Note:  The Apache HTTP Ser…

📅 Published: July 10, 2025, 4:56 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2024-47252 - Apache HTTP Server: mod_ssl error log variable escaping

Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variab…

📅 Published: July 10, 2025, 4:55 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2024-43204 - Apache HTTP Server: SSRF with mod_headers setting Content-Type header

SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker.  Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header with a value provided in the HTTP reques…

📅 Published: July 10, 2025, 4:54 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2024-42516 - Apache HTTP Server: HTTP response splitting

HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Se…

📅 Published: July 10, 2025, 4:53 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-49464 - Zoom Clients for Windows- Classic Buffer Overflow

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

📅 Published: July 10, 2025, 4:32 p.m. 🔄 Last Modified: Aug. 5, 2025, 1:50 p.m.
Total resulsts: 345165
Page 4285 of 34,517
« previous page » next page
Filters