2.3

CVSS4.0

CVE-2025-6534 - xxyopen/201206030 novel-plus File FileController.java remove resource injection

A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of the component File Handler. The manipulation leads to improper con…

πŸ“… Published: June 24, 2025, 12:31 a.m. πŸ”„ Last Modified: July 9, 2025, 7:08 p.m.

6.3

CVSS4.0

CVE-2025-6533 - xxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replay

A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginController.java of the component CATCHA Handler. The manipulation …

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 7:48 p.m.

5.3

CVSS4.0

CVE-2025-6532 - NOYAFA/Xiami LF9 Pro RTSP Live Video Stream Endpoint access control

A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerability is an unknown functionality of the component RTSP Live Video Stream Endpoint. The manipulation leads to improper access controls. The attack can only be initiated within the lo…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 7:49 p.m.

7.1

CVSS3.1

CVE-2024-56917 -

Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 9:48 p.m.

9.8

CVSS3.1

CVE-2021-41691 -

A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:07 p.m.

3.6

CVSS3.1

CVE-2025-4878 - Libssh: use of uninitialized variable in privatekey_from_file()

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 7:34 a.m.

4.2

CVSS3.1

CVE-2025-53021 -

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attack…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 3:23 p.m.

9.8

CVSS3.1

CVE-2024-37743 -

An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:07 p.m.

7.5

CVSS3.1

CVE-2025-44531 -

An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing public key is received during a Bluetooth connection attempt.

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:07 p.m.

5

CVSS3.1

CVE-2025-5372 - Libssh: incorrect return code handling in ssh_kdf() in libssh

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for successβ€”the function may mistaken…

πŸ“… Published: June 24, 2025, midnight πŸ”„ Last Modified: April 7, 2026, 8:30 a.m.
Total resulsts: 343947
Page 4385 of 34,395
Β« previous page Β» next page
Filters