8.6

CVSS4.0

CVE-2025-52557 - Mail-0 Zero Session Hijacking Via Email

Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81.

📅 Published: June 21, 2025, 1:42 a.m. 🔄 Last Modified: June 23, 2025, 8:16 p.m.

9.3

CVSS4.0

CVE-2025-52556 - rfc3161-client has insufficient verification for timestamp response signatures

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the timestamp response signature verification logic. In particular, chain verification is performed against the TSR's embedded certificates up to the trust…

📅 Published: June 21, 2025, 1:33 a.m. 🔄 Last Modified: June 23, 2025, 8:16 p.m.

6.9

CVSS4.0

CVE-2025-6394 - code-projects Simple Online Hotel Reservation System add_reserve.php sql injection

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_reserve.php. The manipulation of the argument firstname leads to sql injection. The attack can be laun…

📅 Published: June 21, 2025, 1:31 a.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.

8.7

CVSS4.0

CVE-2025-6393 - TOTOLINK A702R/A3002R/A3002RU/EX1200T HTTP POST Request formIPv6Addr buffer overflow

A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Han…

📅 Published: June 21, 2025, 1 a.m. 🔄 Last Modified: July 9, 2025, 6:43 p.m.

4.8

CVSS4.0

CVE-2025-6375 - poco MultipartReader.cpp MultipartInputStream null pointer dereference

A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is the function MultipartInputStream of the file Net/src/MultipartReader.cpp. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been …

📅 Published: June 21, 2025, 12:31 a.m. 🔄 Last Modified: Sept. 18, 2025, 1:38 p.m.

7.5

CVSS3.1

CVE-2025-5475 - Sony XAV-AX8500 Bluetooth Packet Handling Integer Overflow Remote Code Execution Vulnerability

Sony XAV-AX8500 Bluetooth Packet Handling Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sony XAV-AX8500 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the…

📅 Published: June 21, 2025, 12:10 a.m. 🔄 Last Modified: July 8, 2025, 2:30 p.m.

7.5

CVSS3.1

CVE-2025-5477 - Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerabi…

Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sony XAV-AX8500 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device…

📅 Published: June 21, 2025, 12:10 a.m. 🔄 Last Modified: July 8, 2025, 2:29 p.m.

8.8

CVSS3.0

CVE-2025-5478 - Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability

Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. The specif…

📅 Published: June 21, 2025, 12:09 a.m. 🔄 Last Modified: July 8, 2025, 2:29 p.m.

7.5

CVSS3.0

CVE-2025-5479 - Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerabi…

Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. An attacker must first obtain the ability to pair a malicious…

📅 Published: June 21, 2025, 12:09 a.m. 🔄 Last Modified: July 8, 2025, 2:29 p.m.

8.8

CVSS3.1

CVE-2025-5476 - Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability

Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the imp…

📅 Published: June 21, 2025, 12:09 a.m. 🔄 Last Modified: July 8, 2025, 2:30 p.m.
Total resulsts: 343947
Page 4404 of 34,395
« previous page » next page
Filters