5.3

CVSS4.0

CVE-2025-8221 - jerryshensjf JPACookieShop 蛋糕商城JPA版 GoodsCustController.java goodsSearch cross site scripting

A vulnerability classified as problematic was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. Affected by this vulnerability is the function goodsSearch of the file GoodsCustController.java. The manipulation of the argument keyword leads to cross site sc…

📅 Published: July 27, 2025, 4:02 a.m. 🔄 Last Modified: Oct. 31, 2025, 7:23 p.m.

6.9

CVSS4.0

CVE-2025-8220 - Engeman Web Password Recovery RecoveryPass sql injection

A vulnerability has been found in Engeman Web up to 12.0.0.2. The affected element is an unknown function of the file /Login/RecoveryPass of the component Password Recovery Page. The manipulation of the argument LanguageCombobox as part of Cookie leads to sql injection. The attack is possible to be…

📅 Published: July 27, 2025, 3:02 a.m. 🔄 Last Modified: Oct. 11, 2025, 10:15 p.m.

5.3

CVSS4.0

CVE-2025-8219 - Shanghai Lingdang Information Technology Lingdang CRM HTTP POST Request tabdetail_moduleSave_dxkp.p…

A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. It has been rated as critical. This issue affects some unknown processing of the file /crm/crmapi/erp/tabdetail_moduleSave_dxkp.php of the component HTTP POST Request Handler. The manipulation of the a…

📅 Published: July 27, 2025, 2:02 a.m. 🔄 Last Modified: Aug. 28, 2025, 12:22 p.m.

4.4

CVSS3.1

CVE-2025-6241 - CVE-2025-6241

LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present in the default installation. If a user-writable directory is present in the SYSTEM PATH environment variable, the user can write a malicious DLL to that directory with arbitrary co…

📅 Published: July 27, 2025, 12:46 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2024-58265 -

The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.

📅 Published: July 27, 2025, midnight 🔄 Last Modified: Aug. 7, 2025, 3:13 p.m.

2.9

CVSS3.1

CVE-2024-58262 - curve25519-dalek: Curve25519-Dalek Scalar Timing Vulnerability

The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.

📅 Published: July 27, 2025, midnight 🔄 Last Modified: Aug. 7, 2025, 2:58 p.m.

3.2

CVSS3.1

CVE-2024-58266 - shlex: Shlex Command Injection Vulnerability

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

📅 Published: July 27, 2025, midnight 🔄 Last Modified: Aug. 7, 2025, 3:18 p.m.

7.2

CVSS3.1

CVE-2025-54597 -

LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.

📅 Published: July 27, 2025, midnight 🔄 Last Modified: Aug. 7, 2025, 1:09 a.m.

3.7

CVSS3.1

CVE-2024-58263 -

The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.

📅 Published: July 27, 2025, midnight 🔄 Last Modified: Aug. 7, 2025, 3:01 p.m.

2.9

CVSS3.1

CVE-2024-58261 - sequoia-openpgp: Sequoia OpenPGP: RawCertParser Infinite Loop Vulnerability

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

📅 Published: July 27, 2025, midnight 🔄 Last Modified: Aug. 6, 2025, 8:59 p.m.
Total resulsts: 349182
Page 4499 of 34,919
« previous page » next page
Filters