9.8

CVSS3.1

CVE-2025-43933 -

fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-37657 -

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: July 10, 2025, 9:20 p.m.

7.5

CVSS3.1

CVE-2025-52492 -

A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credentials for the Twilio API. A remote attacker who obtains a copy of the firmware can extract these credentials. This could allow the attacker to gain unau…

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-25177 - luajit: Out of bounds read in LuaJIT

LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 7:15 p.m.

7.5

CVSS3.1

CVE-2023-51232 -

Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-25178 - luajit: Out of bounds read in LuaJIT

LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-43932 -

JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-43930 -

Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-25176 - luajit: From CVEorg collector

LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-45065 -

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

πŸ“… Published: July 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345149
Page 4372 of 34,515
Β« previous page Β» next page
Filters