5.3

CVSS4.0

CVE-2025-7413 - code-projects Library System profile.php unrestricted upload

A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part of the file /user/teacher/profile.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been di…

πŸ“… Published: July 10, 2025, 8:02 p.m. πŸ”„ Last Modified: July 16, 2025, 3:01 p.m.

7.5

CVSS3.1

CVE-2025-2520 - Dereferencing of an uninitialized pointer leads to denial of service.

The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications. An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which results in a dereferencing of an uninitialized pointer leading to…

πŸ“… Published: July 10, 2025, 7:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-53629 - cpp-httplib Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This…

πŸ“… Published: July 10, 2025, 7:46 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 6:09 p.m.

6.3

CVSS4.0

CVE-2025-53628 - cpp-httplib does not limit the length of a line

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This vulnerability is fixed in 0.20.1. NOTE: This vulnerability is related t…

πŸ“… Published: July 10, 2025, 7:45 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 6:08 p.m.

8.7

CVSS4.0

CVE-2025-53634 - Chall-Manager's HTTP Gateway have no header check timeout leading to potential slow loris attacks

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes headers, but with no timeout set. With a slow loris attack, an attacker could cause Denial of Service (DoS). Exploitation does not require authentication nor authorization, so anyo…

πŸ“… Published: July 10, 2025, 7:39 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 8:41 p.m.

8.7

CVSS4.0

CVE-2025-53633 - Chall-Manager's scenario decoding process does not check for zip bombs

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the size of the decoded content is not checked, potentially leading to zip bombs decompression. Exploitation does not require authentication nor authorization, …

πŸ“… Published: July 10, 2025, 7:38 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 8:44 p.m.

8.8

CVSS4.0

CVE-2025-53632 - Chall-Manager's scenario decoding process does not check for zip slips

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the path of the file to write is not checked, potentially leading to zip slips. Exploitation does not require authentication nor authorization, so anyone can ex…

πŸ“… Published: July 10, 2025, 7:36 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 8:49 p.m.

8.9

CVSS4.0

CVE-2025-53630 - Integer Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in gguf

llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in ggml/src/gguf.cpp can lead to Heap Out-of-Bounds Read/Write. This vulnerability is fixed in commit 26a48ad699d50b6268900062661bd22f3e792579.

πŸ“… Published: July 10, 2025, 7:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-7412 - code-projects Library System profile.php unrestricted upload

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/student/profile.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exp…

πŸ“… Published: July 10, 2025, 7:32 p.m. πŸ”„ Last Modified: July 16, 2025, 3:02 p.m.

9.3

CVSS4.0

CVE-2025-34100 - BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload

An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to uplo…

πŸ“… Published: July 10, 2025, 7:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4683 of 34,919
Β« previous page Β» next page
Filters