2.9

CVSS3.1

CVE-2025-48753 -

In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 9:23 p.m.

2.9

CVSS3.1

CVE-2025-48756 -

In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits (e.g., 5 bits) for group number.

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 5:45 p.m.

2.9

CVSS3.1

CVE-2025-48755 -

In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 8:38 p.m.

2.9

CVSS3.1

CVE-2025-48752 -

In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 9:22 p.m.

6.9

CVSS4.0

CVE-2025-5119 - Emlog Pro api_controller.php sql injection

A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be initiated remotely. The exploit has been disclose…

πŸ“… Published: May 23, 2025, 9 p.m. πŸ”„ Last Modified: June 10, 2025, 7:34 p.m.

7.8

CVSS3.1

CVE-2025-24917 - Improper Access Control leads to Local Privilege Escalation

In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.

πŸ“… Published: May 23, 2025, 3:59 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

7

CVSS3.1

CVE-2025-24916 - Improper Access Control leads to Local Priviledge Escalation

When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default in…

πŸ“… Published: May 23, 2025, 3:46 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

6.6

CVSS4.0

CVE-2025-48375 - Schule Missing Rate Limiting on OTP Email Requests – Susceptible to Abuse & DoS

Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP request functionality. This vulnerability can be…

πŸ“… Published: May 23, 2025, 3:41 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:10 p.m.

6

CVSS4.0

CVE-2025-48377 - Dnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit mode

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Version 9.13.9 fixes the issue.

πŸ“… Published: May 23, 2025, 3:39 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:21 p.m.

6.1

CVSS4.0

CVE-2025-48378 - Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue.

πŸ“… Published: May 23, 2025, 3:39 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:20 p.m.
Total resulsts: 345997
Page 4944 of 34,600
Β« previous page Β» next page
Filters