2.9

CVSS3.1

CVE-2025-32415 - libxml2: Out-of-bounds Read in xmlSchemaIDCFillNodeTables

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.8

CVSS3.1

CVE-2021-47669 - can: vxcan: vxcan_xmit: fix use after free bug

In the Linux kernel, the following vulnerability has been resolved: can: vxcan: vxcan_xmit: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the canfd_frame cfd which aliases skb memory is accessed after the netif_rx_ni().

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

0.0

CVE-2024-56518 -

Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka a client configuration file), which can be uploaded at the /cluster-connections URI.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.5

CVSS3.1

CVE-2025-25457 -

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 12:02 p.m.

9.8

CVSS3.1

CVE-2025-29041 -

An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 4:15 p.m.

0.0

CVE-2025-29044 -

Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via the QUERY_STRING key value

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 12:42 p.m.

0.0

CVE-2024-53924 -

Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

6.1

CVSS3.1

CVE-2025-29015 -

Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

8.1

CVSS3.1

CVE-2025-43715 -

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition.โ€ฆ

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

9.8

CVSS3.1

CVE-2025-28009 -

A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.
Total resulsts: 290933
Page 43 of 29,094
ยซ previous page ยป next page
Filters