2.9
CVE-2025-48753 -
In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.
2.9
CVE-2025-48756 -
In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits (e.g., 5 bits) for group number.
2.9
CVE-2025-48755 -
In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).
2.9
CVE-2025-48752 -
In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.
6.9
CVE-2025-5119 - Emlog Pro api_controller.php sql injection
A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be initiated remotely. The exploit has been discloseβ¦
7.8
CVE-2025-24917 - Improper Access Control leads to Local Privilege Escalation
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.
7
CVE-2025-24916 - Improper Access Control leads to Local Priviledge Escalation
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default inβ¦
6.6
CVE-2025-48375 - Schule Missing Rate Limiting on OTP Email Requests β Susceptible to Abuse & DoS
Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP request functionality. This vulnerability can beβ¦
6
CVE-2025-48377 - Dnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit mode
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Version 9.13.9 fixes the issue.
6.1
CVE-2025-48378 - Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue.