9.8

CVSS3.1

CVE-2025-50472 -

The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_model_meta()` function of the `ModelFileSystemCache()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized `.mdl` pโ€ฆ

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-54939 -

LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 27, 2025, 3:52 p.m.

6.5

CVSS3.1

CVE-2025-50868 -

A SQL Injection vulnerability exists in the takeassessment2.php file of CloudClassroom-PHP-Project 1.0. The Q4 POST parameter is not properly sanitized before being used in SQL queries.

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-45150 -

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request.

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 17, 2025, 6:28 p.m.

7.8

CVSS3.1

CVE-2025-54564 -

uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the nobody user.

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-51502 -

Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 19, 2025, 3:33 p.m.

6.1

CVSS3.1

CVE-2025-50869 -

A stored Cross-Site Scripting (XSS) vulnerability exists in the qureydetails.php page of Institute-of-Current-Students 1.0, where the input fields for Query and Answer do not properly sanitize user input. Authenticated users can inject arbitrary JavaScript code.

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-52327 -

SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 15, 2025, 8:44 p.m.

7.2

CVSS3.1

CVE-2025-44139 -

Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 13, 2025, 3 p.m.

5.8

CVSS3.1

CVE-2019-19145 -

Quantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65536 possible passwords.

๐Ÿ“… Published: Aug. 1, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347806
Page 4305 of 34,781
ยซ previous page ยป next page
Filters