7.5

CVSS3.1

CVE-2025-52520 - Apache Tomcat: DoS via integer overflow in multipart file upload

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following v…

πŸ“… Published: July 10, 2025, 7:05 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2025-52434 - Apache Tomcat: APR/Native Connector crash leading to DoS

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 throu…

πŸ“… Published: July 10, 2025, 7:03 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.9

CVSS4.0

CVE-2025-7411 - code-projects LifeStyle Store success.php sql injection

A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /success.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has bee…

πŸ“… Published: July 10, 2025, 7:02 p.m. πŸ”„ Last Modified: July 16, 2025, 3:02 p.m.

7.8

CVSS3.1

CVE-2025-53503 -

Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

πŸ“… Published: July 10, 2025, 6:59 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:44 a.m.

7.6

CVSS3.1

CVE-2025-53378 -

A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS o…

πŸ“… Published: July 10, 2025, 6:58 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:46 a.m.

7.8

CVSS3.1

CVE-2025-52837 -

Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any file/folder and achieve privilege escalation.

πŸ“… Published: July 10, 2025, 6:57 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.8

CVSS3.1

CVE-2025-52521 -

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

πŸ“… Published: July 10, 2025, 6:57 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.1

CVSS3.1

CVE-2025-53626 - pdfme has Sandbox Escape and Prototype Pollution vulnerabilities in pdfme expression evaluation

pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.

πŸ“… Published: July 10, 2025, 6:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-52473 - liboqs secret-dependent branching in HQC reference implementation when compiled with Clang 17-20

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the HQC key encapsulation mechanism when it is compiled with Clang for optimization levels a…

πŸ“… Published: July 10, 2025, 6:42 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 5:04 p.m.

5.4

CVSS3.1

CVE-2025-53709 - Access control issues impacting secure-upload service

Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The service only installed on a small number of environments. Under specific circumstances, privileged users of secure-upload could have selected email templates not necessarily crea…

πŸ“… Published: July 10, 2025, 6:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4685 of 34,919
Β« previous page Β» next page
Filters