6.5

CVSS3.1

CVE-2025-46203 -

An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.

πŸ“… Published: June 4, 2025, midnight πŸ”„ Last Modified: June 10, 2025, 3:07 p.m.

6.5

CVSS3.1

CVE-2025-23106 -

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.

πŸ“… Published: June 4, 2025, midnight πŸ”„ Last Modified: June 11, 2025, 6:54 p.m.

5.3

CVSS4.0

CVE-2025-5546 - PHPGurukul Daily Expense Tracker System expense-reports-detailed.php sql injection

A vulnerability classified as critical was found in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /expense-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The expl…

πŸ“… Published: June 3, 2025, 11:31 p.m. πŸ”„ Last Modified: June 10, 2025, 3:15 p.m.

5.3

CVSS4.0

CVE-2025-5545 - aaluoxiang oa_system ProcedureController.java image path traversal

A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the function image of the file src/main/java/cn/gson/oasys/controller/process/ProcedureController.java. The manipulation leads to path traversal. It is possi…

πŸ“… Published: June 3, 2025, 11:31 p.m. πŸ”„ Last Modified: June 9, 2025, 3:04 p.m.

5.3

CVSS4.0

CVE-2025-5544 - aaluoxiang oa_system UserpanelController.java image path traversal

A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this issue is the function image of the file src/main/java/cn/gson/oasys/controller/user/UserpanelController.java. The manipulation leads to path traversal…

πŸ“… Published: June 3, 2025, 11 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 6:08 p.m.

7.7

CVSS4.0

CVE-2025-24015 - Deno's AES GCM authentication tags are not verified

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in Deno in which the authentication tag is not being validated. This means tampered ciphertexts or incorrect keys might not be detected, which breaks the g…

πŸ“… Published: June 3, 2025, 10:48 p.m. πŸ”„ Last Modified: June 9, 2025, 3:11 p.m.

4.8

CVSS4.0

CVE-2025-5543 - TOTOLINK X2000R Parent Controls Page cross site scripting

A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Parent Controls Page. The manipulation of the argument Device Name leads to cross site scripting. The attack can be lau…

πŸ“… Published: June 3, 2025, 10:31 p.m. πŸ”„ Last Modified: June 6, 2025, 6:47 p.m.

4.8

CVSS4.0

CVE-2025-5542 - TOTOLINK X2000R Virtual Server Page formPortFw cross site scripting

A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been classified as problematic. Affected is an unknown function of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. It is possible …

πŸ“… Published: June 3, 2025, 10 p.m. πŸ”„ Last Modified: June 6, 2025, 6:47 p.m.

3.5

CVSS3.1

CVE-2025-49000 - InvenTree has uncontrolled memory allocation via built-in label-sheet plugin

InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-se…

πŸ“… Published: June 3, 2025, 8:54 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 3:10 p.m.

9.3

CVSS4.0

CVE-2025-48951 - Auth0-PHP SDK Deserialization of Untrusted Data vulnerability

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafte…

πŸ“… Published: June 3, 2025, 8:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5184 of 34,919
Β« previous page Β» next page
Filters