4.8

CVSS4.0

CVE-2025-8672 - TCC Bypass via Inherited Permissions in Bundled Interpreter in GIMP.app

MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the applicationโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 12:21 p.m. ๐Ÿ”„ Last Modified: Sept. 12, 2025, 2:53 p.m.

4.8

CVSS4.0

CVE-2025-8845 - NASM Netwide Assember nasm.c assemble_file stack-based overflow

A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be usโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 12:02 p.m. ๐Ÿ”„ Last Modified: Sept. 15, 2025, 2:57 p.m.

4.8

CVSS4.0

CVE-2025-8844 - NASM Netwide Assember preproc.c parse_smacro_template null pointer dereference

A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Aug. 11, 2025, 11:32 a.m. ๐Ÿ”„ Last Modified: Sept. 15, 2025, 2:57 p.m.

4.8

CVSS4.0

CVE-2025-8843 - NASM Netwide Assember outmacho.c macho_no_dead_strip heap-based overflow

A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Aug. 11, 2025, 11:02 a.m. ๐Ÿ”„ Last Modified: Sept. 15, 2025, 2:58 p.m.

4.8

CVSS4.0

CVE-2025-8842 - NASM Netwide Assember preproc.c do_directive use after free

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Aug. 11, 2025, 10:32 a.m. ๐Ÿ”„ Last Modified: Sept. 15, 2025, 2:59 p.m.

5.3

CVSS4.0

CVE-2025-8841 - zlt2000 microservices-platform FileController.java upload unrestricted upload

A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads to unrestricted upload. The attack can be laโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 10:02 a.m. ๐Ÿ”„ Last Modified: Sept. 16, 2025, 6:51 p.m.

5.3

CVSS4.0

CVE-2025-8840 - jshERP Endpoint deleteBatch improper authorization

A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of the argument ids leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosedโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 9:32 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 7:09 p.m.

9.3

CVSS4.0

CVE-2025-8853 - 2100 Technology๏ฝœOfficial Document Management System - Authentication Bypass

Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.

๐Ÿ“… Published: Aug. 11, 2025, 9:04 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-8839 - jshERP Endpoint addUser improper authorization

A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be โ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 9:02 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 7 p.m.

6.9

CVSS4.0

CVE-2025-8838 - WinterChenS my-site Backend admin preHandle improper authentication

A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHandle of the file /admin/ of the component Backend Interface. The manipulation of the argument uri leads to improper authentication. The attack can be inโ€ฆ

๐Ÿ“… Published: Aug. 11, 2025, 8:32 a.m. ๐Ÿ”„ Last Modified: Sept. 11, 2025, 5:05 p.m.
Total resulsts: 349182
Page 4352 of 34,919
ยซ previous page ยป next page
Filters