7.3

CVSS4.0

CVE-2025-6384 - Improper Control of Dynamically-Managed Code Resources in Crafter Studio

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Exe…

πŸ“… Published: June 19, 2025, 8:57 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 4:08 p.m.

5.1

CVSS4.0

CVE-2025-6278 - Upsonic server.py os.path.join path traversal

A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/server.py. The manipulation of the argument file.filename leads to path traversal. The exploit has been disclosed to the public and may be used.

πŸ“… Published: June 19, 2025, 8:31 p.m. πŸ”„ Last Modified: July 8, 2025, 4:38 p.m.

5.3

CVSS4.0

CVE-2025-6277 - Brilliance Golden Link Secondary System custTakeInfoPage.htm sql injection

A vulnerability classified as critical has been found in Brilliance Golden Link Secondary System up to 20250609. This affects an unknown part of the file /storagework/custTakeInfoPage.htm. The manipulation of the argument custTradeName leads to sql injection. It is possible to initiate the attack r…

πŸ“… Published: June 19, 2025, 8:29 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 6:42 p.m.

5.3

CVSS4.0

CVE-2025-6276 - Brilliance Golden Link Secondary System rentTakeInfoPage.htm sql injection

A vulnerability was found in Brilliance Golden Link Secondary System up to 20250609. It has been rated as critical. Affected by this issue is some unknown functionality of the file /storagework/rentTakeInfoPage.htm. The manipulation of the argument custTradeName leads to sql injection. The attack m…

πŸ“… Published: June 19, 2025, 8 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 6:44 p.m.

4.8

CVSS4.0

CVE-2025-6275 - WebAssembly wabt binary-reader-interp.cc GetFuncOffset use after free

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-interp.cc. The manipulation leads to use after free. It is possible to launch the attack on the local ho…

πŸ“… Published: June 19, 2025, 7:31 p.m. πŸ”„ Last Modified: July 2, 2025, 6:34 p.m.

4.8

CVSS4.0

CVE-2025-6274 - WebAssembly wabt binary-reader-interp.cc OnDataCount resource consumption

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally is a requirement. The exploit has been disclosed …

πŸ“… Published: June 19, 2025, 7 p.m. πŸ”„ Last Modified: July 2, 2025, 6:33 p.m.

4.8

CVSS4.0

CVE-2025-6273 - WebAssembly wabt binary-reader-objdump.cc LogOpcode assertion

A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclos…

πŸ“… Published: June 19, 2025, 6:31 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 4:24 p.m.

4.8

CVSS4.0

CVE-2025-6272 - wasm3 m3_compile.c MarkSlotAllocated out-of-bounds write

A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the file source/m3_compile.c. The manipulation leads to out-of-bounds write. An attack has to be approached locally. The exploit has been disclosed to the public…

πŸ“… Published: June 19, 2025, 6 p.m. πŸ”„ Last Modified: July 2, 2025, 7:04 p.m.

4.8

CVSS4.0

CVE-2025-6271 - swftools wav2swf wav.c wav_convert2mono out-of-bounds

A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclo…

πŸ“… Published: June 19, 2025, 5:31 p.m. πŸ”„ Last Modified: July 2, 2025, 7:03 p.m.

9.1

CVSS3.1

CVE-2025-33117 - IBM QRadar SIEM command execution

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.

πŸ“… Published: June 19, 2025, 5:16 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.
Total resulsts: 343887
Page 4423 of 34,389
Β« previous page Β» next page
Filters