6.6

CVSS4.0

CVE-2025-53888 - RIOT-OS has an ineffective size check that can lead to buffer overflow in link layer address filter…

RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `assert()` can lead to buffer overflow in versions up to and including 2025.04. Assertions are usually compiled out in production builds. If assertions are the only defense against …

πŸ“… Published: July 18, 2025, 3:32 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 7:39 p.m.

8.7

CVSS4.0

CVE-2025-7790 - D-Link DI-8100 HTTP Request menu_nat.asp stack-based overflow

A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part of the file /menu_nat.asp of the component HTTP Request Handler. The manipulation of the argument out_addr/in_addr/out_port/proto leads to stack-based buffer overflow. It is poss…

πŸ“… Published: July 18, 2025, 3:32 p.m. πŸ”„ Last Modified: July 23, 2025, 4:43 p.m.

6.3

CVSS4.0

CVE-2025-7789 - Xuxueli xxl-job Token Generation IndexController.java makeToken weak password hash

A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to password hash with insuff…

πŸ“… Published: July 18, 2025, 3:14 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 7:35 p.m.

5.4

CVSS3.1

CVE-2025-46732 - OpenCTI's GraphQL IDOR enables authenticated users to modify or delete notifications of other users

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnerability in the GrapQL `NotificationLineNotificationMarkReadMutation` and `NotificationLineNotificationDeleteMutation` mutations of OpenCTI allows an authenticat…

πŸ“… Published: July 18, 2025, 3:05 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:09 p.m.

5.3

CVSS4.0

CVE-2025-7788 - Xuxueli xxl-job SampleXxlJob.java commandJobHandler os command injection

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to os command injection. The attack …

πŸ“… Published: July 18, 2025, 3:02 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 7:52 p.m.

5.3

CVSS4.0

CVE-2025-7787 - Xuxueli xxl-job SampleXxlJob.java httpJobHandler server-side request forgery

A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is possible to launch t…

πŸ“… Published: July 18, 2025, 2:14 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 5:16 p.m.

5.5

CVSS3.1

CVE-2024-13175 - IDOR in Vidco Software's VOC TESTER

Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing.This issue affects VOC TESTER: before 12.41.0.

πŸ“… Published: July 18, 2025, 2:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-7786 - Gnuboard g6 Post Reply qa cross site scripting

A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the file /bbs/scrap_popin_update/qa/ of the component Post Reply Handler. The manipulation leads to cross site scripting. The attack may be initiated remot…

πŸ“… Published: July 18, 2025, 1:14 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 3:48 p.m.

5.3

CVSS4.0

CVE-2025-7785 - thinkgem JeeSite SsoController.java sso redirect

A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the function sso of the file src/main/java/com/jeesite/modules/sys/web/SsoController.java. The manipulation of the argument redirect leads to open redirect. The attack can be initiated r…

πŸ“… Published: July 18, 2025, 11:44 a.m. πŸ”„ Last Modified: Aug. 25, 2025, 5:26 p.m.

2.2

CVSS3.1

CVE-2025-6227 - Invite token is used as part of the secure communication

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.

πŸ“… Published: July 18, 2025, 11:39 a.m. πŸ”„ Last Modified: Oct. 14, 2025, 2:32 p.m.
Total resulsts: 349182
Page 4596 of 34,919
Β« previous page Β» next page
Filters