6.5

CVSS3.1

CVE-2025-48964 - iputils: iputils integer overflow

ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calcula…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-51862 -

Insecure Direct Object Reference (IDOR) vulnerability in TelegAI (telegai.com) thru 2025-05-26 in its chat component. An attacker can exploit this IDOR to tamper other users' conversation. Additionally, malicious contents and XSS payloads can be injected, leading to phishing attack, user spoofing a…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-51864 -

A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, allowing attackers to hijack accounts through stolen JWT tokens.

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-51458 -

SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with api_editor_v1.editor_sql_run, editor_chart_run, and datasource…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 4:09 p.m.

7.3

CVSS3.1

CVE-2025-31511 -

An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user ID in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version equal to or greater than one of the followin…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-51459 -

File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hub._sanitize_filename and plugins_util.scan_p…

πŸ“… Published: July 22, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 4:13 p.m.

8.7

CVSS4.0

CVE-2025-7945 - D-Link DIR-513 formSetWanDhcpplus buffer overflow

A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the file /goform/formSetWanDhcpplus. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. T…

πŸ“… Published: July 21, 2025, 11:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-54432 -

This CVE is a duplicate of another CVE. See CVE-2018-25031 and CVE-2021-46708.

πŸ“… Published: July 21, 2025, 11:18 p.m. πŸ”„ Last Modified: July 29, 2025, 5:15 p.m.

0.0

CVE-2025-54420 -

This CVE is a duplicate of CVE-2025-8129.

πŸ“… Published: July 21, 2025, 11:18 p.m. πŸ”„ Last Modified: July 29, 2025, 5:15 p.m.

5.3

CVSS4.0

CVE-2025-7944 - PHPGurukul Taxi Stand Management System search.php cross site scripting

A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack remotely. The explo…

πŸ“… Published: July 21, 2025, 11:02 p.m. πŸ”„ Last Modified: July 29, 2025, 8:16 p.m.
Total resulsts: 349182
Page 4556 of 34,919
Β« previous page Β» next page
Filters