4.7

CVSS3.1

CVE-2025-55014 -

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-54554 -

tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-51390 -

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Aug. 15, 2025, 4:07 p.m.

4.3

CVSS3.1

CVE-2025-50340 -

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated …

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2025-44961 -

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

8.5

CVSS3.1

CVE-2025-44957 -

Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

9

CVSS3.1

CVE-2025-44954 -

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 5:55 p.m.

9.8

CVSS3.1

CVE-2025-52239 -

An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 4:10 p.m.

9.8

CVSS3.1

CVE-2025-51387 -

The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be execute…

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Oct. 9, 2025, 5:31 p.m.

3.8

CVSS3.1

CVE-2025-46094 - From CVEorg collector

LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.

πŸ“… Published: Aug. 4, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 2:30 p.m.
Total resulsts: 349182
Page 4424 of 34,919
Β« previous page Β» next page
Filters