5.3

CVSS4.0

CVE-2025-48381 - CVAT has information disclosure via browsable API

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an authenticated CVAT user may be able to retrieve the IDs and names of all tasks, projects, labels, and the IDs of all jobs and quality re…

πŸ“… Published: May 30, 2025, 3:38 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 6:11 p.m.

2.3

CVSS4.0

CVE-2025-48068 - Information exposure in Next.js dev server due to lack of origin verification

Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 and 15.0.0 to before 15.2.2, Next.js may have allowed limited source code exposure when the dev server was running with the App Router enabled. The vulnerability only affects loca…

πŸ“… Published: May 30, 2025, 3:37 a.m. πŸ”„ Last Modified: Sept. 10, 2025, 3:17 p.m.

2.9

CVSS4.0

CVE-2025-47952 - Traefik allows path traversal using url encoding

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is configured to route the requests to a backend using a matc…

πŸ“… Published: May 30, 2025, 3:37 a.m. πŸ”„ Last Modified: Nov. 25, 2025, 3:10 p.m.

5.1

CVSS4.0

CVE-2024-12224 - idna accepts Punycode labels that do not produce any non-ASCII when decoded

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.

πŸ“… Published: May 30, 2025, 1:16 a.m. πŸ”„ Last Modified: June 25, 2025, 3:33 p.m.

9.8

CVSS3.1

CVE-2020-36846 - IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotl…

A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library.Β  Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script…

πŸ“… Published: May 30, 2025, 12:50 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-44619 -

Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.

πŸ“… Published: May 30, 2025, midnight πŸ”„ Last Modified: July 22, 2025, 2:28 p.m.

8.8

CVSS3.1

CVE-2025-44904 - hdf5: Heap Buffer Overflow in HDF5 H5VM_memcpyvv Function

hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.

πŸ“… Published: May 30, 2025, midnight πŸ”„ Last Modified: June 3, 2025, 3:35 p.m.

7.5

CVSS3.1

CVE-2025-44614 -

Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext.

πŸ“… Published: May 30, 2025, midnight πŸ”„ Last Modified: July 22, 2025, 2:29 p.m.

5.9

CVSS3.1

CVE-2025-44612 -

Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.

πŸ“… Published: May 30, 2025, midnight πŸ”„ Last Modified: July 22, 2025, 2:29 p.m.

8.8

CVSS3.1

CVE-2025-44905 - hdf5: Heap Buffer Overflow in HDF5 Scale-Offset Filter

hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.

πŸ“… Published: May 30, 2025, midnight πŸ”„ Last Modified: June 3, 2025, 3:35 p.m.
Total resulsts: 347752
Page 5081 of 34,776
Β« previous page Β» next page
Filters