8.7

CVSS4.0

CVE-2025-7077 - Shenzhen Libituo Technology LBT-T300-T310 appy.cgi config_3g_para buffer overflow

A vulnerability classified as critical has been found in Shenzhen Libituo Technology LBT-T300-T310 up to 2.2.3.6. This affects the function config_3g_para of the file /appy.cgi. The manipulation of the argument username_3g/password_3g leads to buffer overflow. It is possible to initiate the attack …

πŸ“… Published: July 6, 2025, 6:32 a.m. πŸ”„ Last Modified: Aug. 20, 2025, 4:30 p.m.

7.8

CVSS3.1

CVE-2025-27446 - Apache APISIX Java Plugin Runner: Local listening file permissions in APISIX plugin runner allow a …

Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges. This issue affects Apache APISIX(java-plugin-runner): from 0.2.0 through 0.5.0. Users ar…

πŸ“… Published: July 6, 2025, 6:05 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

5.3

CVSS4.0

CVE-2025-7076 - BlackVue Dashcam 590X Configuration upload.cgi access control

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.cgi of the component Configuration Handler. The manipulation leads to improper access controls. The attack needs to be initiated…

πŸ“… Published: July 6, 2025, 12:02 a.m. πŸ”„ Last Modified: Oct. 1, 2025, 7:01 p.m.

5.5

CVSS3.1

CVE-2025-38235 - HID: appletb-kbd: fix "appletb_backlight" backlight device reference counting

In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: fix "appletb_backlight" backlight device reference counting During appletb_kbd_probe, probe attempts to get the backlight device by name. When this happens backlight_device_get_by_name looks for a device in the …

πŸ“… Published: July 6, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 4:03 p.m.

5.3

CVSS4.0

CVE-2025-7075 - BlackVue Dashcam 590X HTTP Endpoint upload.cgi unrestricted upload

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /upload.cgi of the component HTTP Endpoint. The manipulation leads to unrestricted upload. The attack needs to be done within t…

πŸ“… Published: July 5, 2025, 11:32 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 7:09 p.m.

5.3

CVSS4.0

CVE-2025-7074 - vercel hyper rimraf-standalone.js ignoreMap redos

A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotel…

πŸ“… Published: July 5, 2025, 9:02 a.m. πŸ”„ Last Modified: Oct. 1, 2025, 7:19 p.m.

5.9

CVSS3.1

CVE-2025-1735 - pgsql extension does not check for errors during escaping

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. ThisΒ could cause crashes if Postgres server rejects the string as invalid.

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2025-47227 -

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeov…

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-53605 - protobuf: Protobuf: Uncontrolled Recursion Vulnerability

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-53604 -

The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.

πŸ“… Published: July 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4779 of 34,919
Β« previous page Β» next page
Filters