9.3
CVE-2012-10037 - PhpTax pfilez Parameter Exec Remote Code Injection
PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A remote attacker can inject arbitrary shell commands, leading to code execution under the web server's context. No authenticaβ¦
5.3
CVE-2025-8859 - code-projects eBlog Site File Upload save-slider.php unrestricted upload
A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File Upload Module. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit hβ¦
4.1
CVE-2025-8865 - yugabytedb: YugabyteDB null pointer dereference
The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.
5.3
CVE-2025-8852 - WuKongOpenSource WukongCRM API Response upload information exposure
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has β¦
4.8
CVE-2025-8851 - LibTIFF tiffcrop tiffcrop.c readSeparateStripsetoBuffer stack-based overflow
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is ideβ¦
6.8
CVE-2025-8864 - yugabytedb: YugabyteDB token exposure
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs
7
CVE-2025-8863 - yugabytedb: YugabyteDB information exposure
YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission
5.1
CVE-2025-8847 - yangzongzhuan RuoYi edit cross site scripting
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the file /system/notice/edit. The manipulation of the argument noticeTitle/noticeContent leads to cross site scripting. The attack can be launched remotely. The exploit has been discβ¦
7
CVE-2025-8862 - yugabytedb: YugabyteDB information exposure
YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.
4.8
CVE-2025-8846 - NASM Netwide Assember parser.c parse_line stack-based overflow
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.