8.7
CVE-2025-7077 - Shenzhen Libituo Technology LBT-T300-T310 appy.cgi config_3g_para buffer overflow
A vulnerability classified as critical has been found in Shenzhen Libituo Technology LBT-T300-T310 up to 2.2.3.6. This affects the function config_3g_para of the file /appy.cgi. The manipulation of the argument username_3g/password_3g leads to buffer overflow. It is possible to initiate the attack β¦
7.8
CVE-2025-27446 - Apache APISIX Java Plugin Runner: Local listening file permissions in APISIX plugin runner allow a β¦
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges. This issue affects Apache APISIX(java-plugin-runner): from 0.2.0 through 0.5.0. Users arβ¦
5.3
CVE-2025-7076 - BlackVue Dashcam 590X Configuration upload.cgi access control
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.cgi of the component Configuration Handler. The manipulation leads to improper access controls. The attack needs to be initiatedβ¦
5.5
CVE-2025-38235 - HID: appletb-kbd: fix "appletb_backlight" backlight device reference counting
In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: fix "appletb_backlight" backlight device reference counting During appletb_kbd_probe, probe attempts to get the backlight device by name. When this happens backlight_device_get_by_name looks for a device in the β¦
5.3
CVE-2025-7075 - BlackVue Dashcam 590X HTTP Endpoint upload.cgi unrestricted upload
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /upload.cgi of the component HTTP Endpoint. The manipulation leads to unrestricted upload. The attack needs to be done within tβ¦
5.3
CVE-2025-7074 - vercel hyper rimraf-standalone.js ignoreMap redos
A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotelβ¦
5.9
CVE-2025-1735 - pgsql extension does not check for errors during escaping
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. ThisΒ could cause crashes if Postgres server rejects the string as invalid.
7.5
CVE-2025-47227 -
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeovβ¦
5.9
CVE-2025-53605 - protobuf: Protobuf: Uncontrolled Recursion Vulnerability
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.
4
CVE-2025-53604 -
The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.