4.3

CVSS3.1

CVE-2025-48735 -

A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230220 allows remote attackers to obtain sensitive information from the database via crafted input in the request body.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-48738 -

An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows unauthenticated remote attackers to use the password reset feature without limits. This can lead to several consequences, including mailbox storage exh…

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.9

CVSS3.1

CVE-2023-53154 - cjson: Heap based buffer overflow at cJSON_ParseWithLength function

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

4

CVSS3.1

CVE-2025-48708 - Ghostscript: Ghostscript Argument Sanitization Vulnerability

gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

5.4

CVSS3.1

CVE-2025-48701 -

openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.

πŸ“… Published: May 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-4692 - ABUP IoT Cloud Platform Incorrect Privilege Assignment

Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by…

πŸ“… Published: May 22, 2025, 11:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-4338 - Lantronix Device Installer Improper Restriction of XML External Entity Reference

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Ins…

πŸ“… Published: May 22, 2025, 11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS4.0

CVE-2025-48371 - OpenFGA Authorization Bypass

OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users are affected un…

πŸ“… Published: May 22, 2025, 10:20 p.m. πŸ”„ Last Modified: Jan. 15, 2026, 2:34 a.m.

8.8

CVSS3.1

CVE-2025-47181 - Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

πŸ“… Published: May 22, 2025, 10:03 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 7:20 p.m.

4.8

CVSS4.0

CVE-2025-4975 - Tapo privilege escalation on shared devices using notifications

When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notification grants full access to the power settings of that device.

πŸ“… Published: May 22, 2025, 9:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347752
Page 5138 of 34,776
Β« previous page Β» next page
Filters