7.5

CVSS3.1

CVE-2025-26783 -

An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, W1000, Modem 5300, and Modem 5400. Incorrect handling of undefined values leads to a Denial of Service.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: July 1, 2025, 3 p.m.

4.6

CVSS3.1

CVE-2025-25370 -

An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive information via the show app only setting function.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: May 16, 2025, 2:43 p.m.

5.5

CVSS3.1

CVE-2023-53146 - media: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer()

In the Linux kernel, the following vulnerability has been resolved: media: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer() In dw2102_i2c_transfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally rea…

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:18 a.m.

8.8

CVSS3.1

CVE-2024-54780 -

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arb…

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 1:03 p.m.

5.4

CVSS3.1

CVE-2024-54779 -

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 2:51 p.m.

6.1

CVSS3.1

CVE-2025-29689 -

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 7:59 p.m.

7.5

CVSS3.1

CVE-2024-55569 -

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: July 1, 2025, 3 p.m.

4.8

CVSS3.1

CVE-2025-44184 -

SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 2:31 p.m.

7.5

CVSS3.1

CVE-2025-44879 -

WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: May 16, 2025, 2:43 p.m.

6.1

CVSS3.1

CVE-2025-29690 -

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the outtype parameter at /address/AddrController.java.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 7:59 p.m.
Total resulsts: 344670
Page 4966 of 34,467
Β« previous page Β» next page
Filters