7.8

CVSS3.1

CVE-2025-0831 - Out-Of-Bounds Read vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on…

Out-Of-Bounds Read vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted JT file.

πŸ“… Published: July 15, 2025, 3 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS3.1

CVE-2025-53622 - DSpace has path traversal vulnerability in Simple Archive Format (SAF) package import via contents …

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.4, 8.2, and 9.1, a path traversal vulnerability is possible during the import of an archive (in Simple Archive Format), either from command-line (`./dspace import` comma…

πŸ“… Published: July 15, 2025, 2:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS3.1

CVE-2025-53621 - DSpace vulnerable to XML External Entity (XXE) injection in import via Simple Archive Format (SAF) …

DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all versions of DSpace prior to 7.6.4, 8.2, and 9.1. External entities are not disabled when parsing XML files during impo…

πŸ“… Published: July 15, 2025, 2:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-30483 -

Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

πŸ“… Published: July 15, 2025, 2:30 p.m. πŸ”„ Last Modified: Aug. 2, 2025, 1:26 a.m.

6.4

CVSS3.1

CVE-2025-33097 - IBM QRadar SIEM cross-site scripting

IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: July 15, 2025, 2:29 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 1:34 a.m.

5.6

CVSS3.1

CVE-2025-48795 - Apache CXF: Denial of Service and sensitive data exposure in logs

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory ex…

πŸ“… Published: July 15, 2025, 2:26 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

7.2

CVSS4.0

CVE-2025-6965 - Integer Truncation on SQLite

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

πŸ“… Published: July 15, 2025, 1:44 p.m. πŸ”„ Last Modified: April 20, 2026, 5 p.m.

8.7

CVSS4.0

CVE-2025-34107 - WinaXe 7.7 FTP Client Remote Buffer Overflow

A buffer overflow vulnerability exists in the WinaXe FTP Client version 7.7 within the FTP banner parsing functionality, WCMDPA10.dll. When the client connects to a remote FTP server and receives an overly long '220 Server Ready' response, the vulnerable component responsible for parsing the banner…

πŸ“… Published: July 15, 2025, 1:11 p.m. πŸ”„ Last Modified: April 22, 2026, 10:30 p.m.

9.3

CVSS4.0

CVE-2025-34103 - WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi

An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling in the undocumented /cgi-bin/rdfs.cgi endpoint. The Client parameter is not sanitized before being passed to a system call, allowing an unauthenticated…

πŸ“… Published: July 15, 2025, 1:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-34111 - Tiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCE

An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of the web server. The v…

πŸ“… Published: July 15, 2025, 1:09 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.
Total resulsts: 349182
Page 4642 of 34,919
Β« previous page Β» next page
Filters