0.0

CVE-2024-53945 -

The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploita…

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 2:05 p.m.

0.0

CVE-2025-50817 -

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker wh…

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 5:11 p.m.

0.0

CVE-2025-52335 -

EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 5:18 p.m.

0.0

CVE-2025-51986 -

An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12 allowing attackers to reach an infinite loop via a crafted length value for a packet.

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 5:36 p.m.

0.0

CVE-2023-43683 -

An issue was discovered in Malwarebytes 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). A Stack buffer out-of-bounds access exists because of an integer underflow when handling newline characters.

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 4:59 p.m.

0.0

CVE-2023-43692 -

An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). Out-of-bound reads in strings detection utilities lead to system crashes.

πŸ“… Published: Aug. 14, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 5:03 p.m.

6.5

CVSS3.1

CVE-2025-55198 - Helm May Panic Due To Incorrect YAML Content

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring YAML files are formatted as Helm expects …

πŸ“… Published: Aug. 13, 2025, 11:23 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 12:15 a.m.

6.5

CVSS3.1

CVE-2025-55199 - Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been resolved in Helm 3.18.5. A workaround involves ens…

πŸ“… Published: Aug. 13, 2025, 11:23 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 12:15 a.m.

6.6

CVSS4.0

CVE-2025-55197 - pypdf's Manipulated FlateDecode streams can exhaust RAM

pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malicious cross-reference stream. Other content streams are affect…

πŸ“… Published: Aug. 13, 2025, 11:03 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 11:15 p.m.

7.1

CVSS4.0

CVE-2025-55196 - External Secrets Operator Missing Namespace Restriction in PushSecret and SecretStore List() Calls …

External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15.0 to before 0.19.2, a vulnerability was discovered where the List() calls for Kubernetes Secret and SecretStore resources performed by the PushSecret controller did not apply a n…

πŸ“… Published: Aug. 13, 2025, 10:54 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 11:15 p.m.
Total resulsts: 305848
Page 50 of 30,585
Β« previous page Β» next page
Filters