9.3

CVSS4.0

CVE-2012-10037 - PhpTax pfilez Parameter Exec Remote Code Injection

PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A remote attacker can inject arbitrary shell commands, leading to code execution under the web server's context. No authentica…

πŸ“… Published: Aug. 11, 2025, 2:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-8859 - code-projects eBlog Site File Upload save-slider.php unrestricted upload

A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File Upload Module. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit h…

πŸ“… Published: Aug. 11, 2025, 2:32 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

4.1

CVSS4.0

CVE-2025-8865 - yugabytedb: YugabyteDB null pointer dereference

The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.

πŸ“… Published: Aug. 11, 2025, 2:19 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-8852 - WuKongOpenSource WukongCRM API Response upload information exposure

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has …

πŸ“… Published: Aug. 11, 2025, 2:02 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 6:45 p.m.

4.8

CVSS4.0

CVE-2025-8851 - LibTIFF tiffcrop tiffcrop.c readSeparateStripsetoBuffer stack-based overflow

A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is ide…

πŸ“… Published: Aug. 11, 2025, 1:32 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 9:10 p.m.

6.8

CVSS4.0

CVE-2025-8864 - yugabytedb: YugabyteDB token exposure

Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs

πŸ“… Published: Aug. 11, 2025, 1:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-8863 - yugabytedb: YugabyteDB information exposure

YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission

πŸ“… Published: Aug. 11, 2025, 1:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-8847 - yangzongzhuan RuoYi edit cross site scripting

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the file /system/notice/edit. The manipulation of the argument noticeTitle/noticeContent leads to cross site scripting. The attack can be launched remotely. The exploit has been disc…

πŸ“… Published: Aug. 11, 2025, 1:02 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 3:32 p.m.

7

CVSS4.0

CVE-2025-8862 - yugabytedb: YugabyteDB information exposure

YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

πŸ“… Published: Aug. 11, 2025, 12:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-8846 - NASM Netwide Assember parser.c parse_line stack-based overflow

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Aug. 11, 2025, 12:32 p.m. πŸ”„ Last Modified: Sept. 15, 2025, 2:59 p.m.
Total resulsts: 349182
Page 4351 of 34,919
Β« previous page Β» next page
Filters