8.1

CVSS3.1

CVE-2025-28062 -

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 2:13 p.m.

5.5

CVSS3.1

CVE-2024-58237 - bpf: consider that tail calls invalidate packet pointers

In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet pointers Tail-called programs could execute any of the helpers that invalidate packet pointers. Hence, conservatively assume that each tail call invalidates packet pointers. Making…

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:35 p.m.

6.5

CVSS3.1

CVE-2024-57232 -

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:41 p.m.

6.5

CVSS3.1

CVE-2024-57231 -

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:41 p.m.

6.5

CVSS3.1

CVE-2024-57229 -

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:40 p.m.

9.8

CVSS3.1

CVE-2025-45615 -

Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 3:18 p.m.

7.5

CVSS3.1

CVE-2025-45608 -

Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 7:07 p.m.

9.1

CVSS3.1

CVE-2025-45238 -

foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 5:39 p.m.

6.5

CVSS3.1

CVE-2024-57235 -

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:42 p.m.

5.5

CVSS3.1

CVE-2024-58098 - bpf: track changes_pkt_data property for global functions

In the Linux kernel, the following vulnerability has been resolved: bpf: track changes_pkt_data property for global functions When processing calls to certain helpers, verifier invalidates all packet pointers in a current state. For example, consider the following program: __attribute__((__n…

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:35 p.m.
Total resulsts: 343738
Page 5013 of 34,374
Β« previous page Β» next page
Filters