5.1

CVSS4.0

CVE-2025-55159 - slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check

slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing access to uninitialized memory. This could lead to undefined behavior or potential crashes. This hasโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 11 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-55157 - Vim heap use-after-free vulnerability when processing recursive tuple data types

Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during evaluation can trigger a use-after-free in Vimโ€™s internal tuple reference management. Specifically, the tuple_unref() function may access alreaโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:54 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 6:50 p.m.

6.9

CVSS4.0

CVE-2025-55158 - Vim double-free vulnerability during Vim9 script import operations

Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, an error during evaluation can trigger a double-free in Vimโ€™s internal typed value (typval_T) management. Specifically, the clear_tv() fโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:54 p.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 6:49 p.m.

8.6

CVSS3.1

CVE-2025-55161 - Stirling-PDF SSRF vulnerability on /api/v1/convert/markdown/pdf

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/markdown/pdf endpoint to convert Markdown to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitizatโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:28 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 6:05 p.m.

7.8

CVSS4.0

CVE-2025-55156 - PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter

pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This issue has been patched โ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-55150 - Stirling-PDF SSRF vulnerability on /api/v1/convert/html/pdf

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitization whicโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 9:57 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 6:08 p.m.

8.6

CVSS3.1

CVE-2025-55151 - Stirling-PDF SSRF vulnerability on /api/v1/convert/file/pdf

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, the "convert file to pdf" functionality (/api/v1/convert/file/pdf) uses LibreOffice's unoconvert tool for conversion, and SSRF vulnerabilities exist during the conversion process.โ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 9:56 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 6:06 p.m.

8.6

CVSS3.1

CVE-2025-25235 - Omnissa Secure Email Gateway (SEG) updates address Server-Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traffic such as HTTP requests to internal networks.

๐Ÿ“… Published: Aug. 11, 2025, 9:47 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-54992 - OpenKilda XXE in SAML configuration

OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is runniโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 9:34 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-55012 - Zed AI Agent Remote Code Execution

Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by bypassing user permission checks. An AI Agent could have exploited a permissions bypass vulnerability to create or modify a project-specific configuraโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 9:25 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4347 of 34,919
ยซ previous page ยป next page
Filters