7.3

CVSS3.1

CVE-2025-54865 - Tilesheets MediaWiki Extension is Vulnerable to Potential SQL Injection

Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.

๐Ÿ“… Published: Aug. 5, 2025, 12:03 a.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:33 p.m.

5.5

CVSS3.1

CVE-2025-54871 - Electron Capture is Vulnerable to TCC Bypass via Misconfigured Node Fuses (macOS)

Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment variable allows arbitrary Node.js code to be eโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:03 a.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:33 p.m.

8.7

CVSS4.0

CVE-2025-54870 - VTun-ng's failure to initialize encryption modules may cause reversion to plaintext

VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules might cause reversion to plaintext due to insufficient error handling. The bug was first introduced in VTun-ng version 3.0.12. This is fixed in version 3.0.18. To workaround this โ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-8535 - cronoh NanoVault xrb URL main.js executeJavaScript cross site scripting

A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, 12:02 a.m. ๐Ÿ”„ Last Modified: Sept. 12, 2025, 4:04 p.m.

6.5

CVSS3.1

CVE-2025-45512 -

A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 2, 2025, 5:35 p.m.

6.5

CVSS3.1

CVE-2025-51627 -

Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privileges to Administrator.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-29745 -

A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-51060 -

An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as IoControlCodes to perform RDMSR and WRMSR, respectively. Through this process, the attacker can modify MSR_LSTAR and hook KiSystemCall64. Afterward, usโ€ฆ

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 9, 2025, 5:33 p.m.

5.4

CVSS3.1

CVE-2025-50592 -

Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 15, 2025, 4:06 p.m.

6.5

CVSS3.1

CVE-2025-52237 -

An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

๐Ÿ“… Published: Aug. 5, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 15, 2025, 4:04 p.m.
Total resulsts: 349182
Page 4414 of 34,919
ยซ previous page ยป next page
Filters