6.9

CVSS4.0

CVE-2025-8327 - code-projects Exam Form Submission delete_s8.php sql injection

A vulnerability classified as critical was found in code-projects Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_s8.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has b…

πŸ“… Published: July 30, 2025, 5:32 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 8:48 p.m.

7.3

CVSS3.1

CVE-2025-36611 -

Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.

πŸ“… Published: July 30, 2025, 4:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.1

CVSS3.1

CVE-2025-8312 -

Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service.This issue affects the following version(s) : * Devolutions Server 2025.2.2.0 through 2025.2.…

πŸ“… Published: July 30, 2025, 4:10 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 1:15 p.m.

5.9

CVSS3.1

CVE-2025-8353 -

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.

πŸ“… Published: July 30, 2025, 4:06 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 2:37 p.m.

6.5

CVSS3.1

CVE-2025-54656 - Apache Struts Extras: Improper Output Neutralization for Logs

** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affects Apache Struts Extras: before 2. When using LookupDispatchAction, in some cases, Struts may print untrusted input to the logs without any filtering. Specially-crafted input ma…

πŸ“… Published: July 30, 2025, 3:58 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.9

CVSS3.1

CVE-2023-2593 - Kernel: ksmbd memory exhaustion denial-of-service vulnerability

A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service condition on the system.

πŸ“… Published: July 30, 2025, 3:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-54573 - CVAT vulnerable to email verification bypass by use of basic authentication

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP Authentication. As a result, users could create accounts using fake email addresses and use the product as verified use…

πŸ“… Published: July 30, 2025, 2:32 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 3:52 p.m.

6.9

CVSS4.0

CVE-2025-43018 - Certain HP LaserJet Pro Printers – Potential Information Disclosure

Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book.

πŸ“… Published: July 30, 2025, 2:31 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 2:37 p.m.

7.2

CVSS4.0

CVE-2025-54433 - Bugsink is vulnerable to Path Traversal attacks via event_id in ingestion

Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, and 1.7.0 through 1.7.3, ingestion paths construct file locations directly from untrusted event_id input without validation. A specially crafted event_id can result in paths outs…

πŸ“… Published: July 30, 2025, 2:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.1

CVE-2025-53944 - AutoGPT Platform Exposes Graph Execution Results via Authorization Gap

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external API's get_graph_execution_results endpoint has an authorization bypass vulnerability. While it correctly validates user access to the graph_id, it fail…

πŸ“… Published: July 30, 2025, 2:28 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 2:40 p.m.
Total resulsts: 349182
Page 4459 of 34,919
Β« previous page Β» next page
Filters