3.5

CVSS3.1

CVE-2025-49000 - InvenTree has uncontrolled memory allocation via built-in label-sheet plugin

InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-se…

📅 Published: June 3, 2025, 8:54 p.m. 🔄 Last Modified: Dec. 17, 2025, 3:10 p.m.

9.3

CVSS4.0

CVE-2025-48951 - Auth0-PHP SDK Deserialization of Untrusted Data vulnerability

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafte…

📅 Published: June 3, 2025, 8:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2025-49002 - Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v…

📅 Published: June 3, 2025, 8:37 p.m. 🔄 Last Modified: June 5, 2025, 2:07 p.m.

7.7

CVSS4.0

CVE-2025-49001 - Dataease Authentication Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds are available.

📅 Published: June 3, 2025, 8:33 p.m. 🔄 Last Modified: June 5, 2025, 2:07 p.m.

6.8

CVSS4.0

CVE-2025-48999 - Dataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE Vulnerability

DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, it will not enter the if statement and will …

📅 Published: June 3, 2025, 8:31 p.m. 🔄 Last Modified: June 5, 2025, 2:07 p.m.

8.7

CVSS4.0

CVE-2025-5527 - Tenda RX3 SetStaticRouteCfg save_staticroute_data stack-based overflow

A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotel…

📅 Published: June 3, 2025, 8:31 p.m. 🔄 Last Modified: June 9, 2025, 3:11 p.m.

6.3

CVSS4.0

CVE-2025-5525 - Jrohy trojan linux.go LogChan os command injection

A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/util/linux.go. The manipulation of the argument c leads to os command injection. The attack can be initiated remotely. The complexity of an at…

📅 Published: June 3, 2025, 8 p.m. 🔄 Last Modified: June 6, 2025, 5:27 p.m.

5.1

CVSS4.0

CVE-2025-5523 - enilu web-flash File Upload upload fileService.upload cross site scripting

A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripti…

📅 Published: June 3, 2025, 7:31 p.m. 🔄 Last Modified: June 9, 2025, 3:12 p.m.

6.9

CVSS4.0

CVE-2025-35036 - hibernate-validator insecure default Expression Language interpolation

Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of…

📅 Published: June 3, 2025, 7:27 p.m. 🔄 Last Modified: Sept. 18, 2025, 2:19 p.m.

6.9

CVSS4.0

CVE-2025-5522 - jack0240 魏 bskms 蓝天幼儿园管理系统 User Creation addUser improper authorization

A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the component User Creation Handler. The manipulation leads to improper authorizatio…

📅 Published: June 3, 2025, 7 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346624
Page 4929 of 34,663
« previous page » next page
Filters