0.0

CVE-2025-43898 -

Not used

πŸ“… Published: April 18, 2025, 2:46 p.m. πŸ”„ Last Modified: April 19, 2025, 3:15 a.m.

0.0

CVE-2025-43897 -

Not used

πŸ“… Published: April 18, 2025, 2:46 p.m. πŸ”„ Last Modified: April 19, 2025, 3:15 a.m.

0.0

CVE-2025-43896 -

Not used

πŸ“… Published: April 18, 2025, 2:46 p.m. πŸ”„ Last Modified: April 19, 2025, 3:15 a.m.

0.0

CVE-2025-43893 -

Not used

πŸ“… Published: April 18, 2025, 2:46 p.m. πŸ”„ Last Modified: April 19, 2025, 3:15 a.m.

4.8

CVSS4.0

CVE-2025-3791 - symisc UnQLite unqlite.c jx9MemObjStore heap-based overflow

A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This vulnerability affects the function jx9MemObjStore of the file /data/src/benchmarks/unqlite/unqlite.c. The manipulation leads to heap-based buffer overflow. It is possible to launc…

πŸ“… Published: April 18, 2025, 2:31 p.m. πŸ”„ Last Modified: April 18, 2025, 2:31 p.m.

0.0

CVE-2025-37838 - HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition

In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition In the ssi_protocol_probe() function, &ssi->work is bound with ssip_xmit_work(), In ssip_pn_setup(), the ssip_pn_xmit() function wit…

πŸ“… Published: April 18, 2025, 2:20 p.m. πŸ”„ Last Modified: April 18, 2025, 2:20 p.m.

6.9

CVSS4.0

CVE-2025-3790 - baseweb JSite Apache Druid Monitoring Console index.html access control

A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /druid/index.html of the component Apache Druid Monitoring Console. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit ha…

πŸ“… Published: April 18, 2025, 1 p.m. πŸ”„ Last Modified: April 18, 2025, 1 p.m.

5.1

CVSS4.0

CVE-2025-3789 - baseweb JSite save cross site scripting

A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /a/sys/area/save. The manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclos…

πŸ“… Published: April 18, 2025, 12:31 p.m. πŸ”„ Last Modified: April 18, 2025, 12:31 p.m.

6.3

CVSS3.1

CVE-2025-32790 - Dify Allows Insecure User Role Access Control for APP DSL Exporting

Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in '/export' should only allow administrator users to export DSL. A patched version ha…

πŸ“… Published: April 18, 2025, 12:15 p.m. πŸ”„ Last Modified: April 18, 2025, 12:15 p.m.

6.3

CVSS3.1

CVE-2024-45651 - IBM Sterling Connect:Direct Web Services session fixation

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.

πŸ“… Published: April 18, 2025, 11:04 a.m. πŸ”„ Last Modified: April 18, 2025, 11:04 a.m.
Total resulsts: 290933
Page 5 of 29,094
Β« previous page Β» next page
Filters