6.5

CVSS3.1

CVE-2025-50420 -

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 5:43 p.m.

6.5

CVSS3.1

CVE-2025-46206 -

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recu…

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 5:39 p.m.

9.8

CVSS3.1

CVE-2025-50341 -

A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false conditions, potentially leading to data exposure or further exploitation.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.9

CVSS3.1

CVE-2025-50422 - poppler: Poppler crash on malformed input

Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-44958 -

RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

9

CVSS3.1

CVE-2025-44963 -

RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

5.3

CVSS3.1

CVE-2025-5988 - Aap-gateway: csrf origin checking is disabled

A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.1

CVE-2025-53394 -

Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed executable placed in the same directory. When a user with administrative privileges opens the crafted backup file and proce…

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-51536 -

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Sept. 23, 2025, 7:08 p.m.

9.6

CVSS3.1

CVE-2025-50754 -

Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack the admin session and, by leveraging the temp…

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347919
Page 4296 of 34,792
Β« previous page Β» next page
Filters