6.6

CVSS4.0

CVE-2025-54874 - OpenJPEG allows OOB heap memory write in opj_jp2_read_header

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

📅 Published: Aug. 5, 2025, 2:33 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

5.4

CVSS3.1

CVE-2025-46958 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

📅 Published: Aug. 5, 2025, 2:32 p.m. 🔄 Last Modified: Aug. 6, 2025, 1:47 p.m.

6.1

CVSS3.1

CVE-2024-52890 - IBM Engineering Lifecycle Optimization - Publishing cross-site scripting

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

📅 Published: Aug. 5, 2025, 1:45 p.m. 🔄 Last Modified: Aug. 14, 2025, 1:57 a.m.

8.4

CVSS4.0

CVE-2025-7033 - Rockwell Automation Heap-based Buffer Overflow In Arena® Simulation

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute code or disclose infor…

📅 Published: Aug. 5, 2025, 1:42 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

8.4

CVSS4.0

CVE-2025-7032 - Rockwell Automation Stack-based Buffer Overflow In Arena® Simulation

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute code or disclose infor…

📅 Published: Aug. 5, 2025, 1:39 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

8.4

CVSS4.0

CVE-2025-7025 - Rockwell Automation Heap-based Buffer Overflow In Arena® Simulation

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute code or disclose infor…

📅 Published: Aug. 5, 2025, 1:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

9.4

CVSS3.1

CVE-2025-54987 -

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture.

📅 Published: Aug. 5, 2025, 1 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

9.4

CVSS3.1

CVE-2025-54948 -

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

📅 Published: Aug. 5, 2025, 1 p.m. 🔄 Last Modified: Oct. 31, 2025, 2:42 p.m.

5.1

CVSS4.0

CVE-2025-8555 - atjiu pybbs search cross site scripting

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown function of the file /search. The manipulation of the argument keyword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to th…

📅 Published: Aug. 5, 2025, 9:32 a.m. 🔄 Last Modified: Sept. 2, 2025, 7:24 p.m.

4.8

CVSS4.0

CVE-2025-8554 - atjiu pybbs list cross site scripting

A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some unknown processing of the file /admin/user/list. The manipulation of the argument Username leads to cross site scripting. The attack may be initiated remotely. The exploit has be…

📅 Published: Aug. 5, 2025, 9:02 a.m. 🔄 Last Modified: Sept. 2, 2025, 7:24 p.m.
Total resulsts: 349182
Page 4408 of 34,919
« previous page » next page
Filters