8.7

CVSS4.0

CVE-2025-48997 - Multer vulnerable to Denial of Service via unhandled exception

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an upload file request with an empty string field name. This request causeโ€ฆ

๐Ÿ“… Published: June 3, 2025, 6:21 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-48953 - Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads

Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.0, it's possible to upload a file that doesn't adhere with the configured allowable file extensions via a manipulated API request. The issue is patched in versions 15.4.2 and 16.0โ€ฆ

๐Ÿ“… Published: June 3, 2025, 6:19 p.m. ๐Ÿ”„ Last Modified: Sept. 22, 2025, 1:54 p.m.

5.8

CVSS4.0

CVE-2025-48950 - MaxKB Python Sandbox Bypass in Function Library

MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/bin,/usr/bin`, etc. Therefore, attackers can exploit some files with execution permissions in non blacklisted directoriโ€ฆ

๐Ÿ“… Published: June 3, 2025, 6:16 p.m. ๐Ÿ”„ Last Modified: Aug. 6, 2025, 7:13 p.m.

6.9

CVSS4.0

CVE-2025-5520 - Open5GS AMF/MME emm_state_authentication assertion

A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack remotely. The exploit has โ€ฆ

๐Ÿ“… Published: June 3, 2025, 6 p.m. ๐Ÿ”„ Last Modified: June 9, 2025, 3:13 p.m.

4.8

CVSS4.0

CVE-2025-5516 - TOTOLINK X2000R URL Filtering Page formFilter cross site scripting

A vulnerability, which was classified as problematic, was found in TOTOLINK X2000R 1.0.0-B20230726.1108. This affects an unknown part of the file /boafrm/formFilter of the component URL Filtering Page. The manipulation of the argument URL Address leads to cross site scripting. It is possible to iniโ€ฆ

๐Ÿ“… Published: June 3, 2025, 6 p.m. ๐Ÿ”„ Last Modified: June 6, 2025, 5:42 p.m.

6.5

CVSS3.1

CVE-2025-30360 - webpack-dev-server users' source code may be stolen when they access a malicious web site with non-โ€ฆ

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when you access a malicious web site with non-Chromium based browser. The `Origin` header is checked to prevent Cross-siโ€ฆ

๐Ÿ“… Published: June 3, 2025, 5:41 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 6:26 p.m.

5.3

CVSS3.1

CVE-2025-30359 - webpack-dev-server users' source code may be stolen when they access a malicious web site

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when they access a malicious web site. Because the request for classic script by a script tag is not subject to same oriโ€ฆ

๐Ÿ“… Published: June 3, 2025, 5:39 p.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 1:12 a.m.

5.3

CVSS4.0

CVE-2025-5515 - TOTOLINK X2000R formMapDel command injection

A vulnerability, which was classified as critical, has been found in TOTOLINK X2000R 1.0.0-B20230726.1108. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel. The manipulation of the argument devicemac1 leads to command injection. The attack may be launched remotelyโ€ฆ

๐Ÿ“… Published: June 3, 2025, 5:31 p.m. ๐Ÿ”„ Last Modified: June 17, 2025, 8:40 p.m.

5.1

CVSS4.0

CVE-2025-5513 - quequnlong shiyi-blog add cross site scripting

A vulnerability has been found in quequnlong shiyi-blog up to 1.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/api/comment/add. The manipulation of the argument content leads to cross site scripting. The attack can be launched remoโ€ฆ

๐Ÿ“… Published: June 3, 2025, 5:31 p.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 1:07 a.m.

6.9

CVSS4.0

CVE-2025-5512 - quequnlong shiyi-blog Administrator Backend verifyPassword improper authentication

A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file /api/sys/user/verifyPassword/ of the component Administrator Backend. The manipulation leads to improper authentication. It is possible to launch the attackโ€ฆ

๐Ÿ“… Published: June 3, 2025, 5 p.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 1:14 a.m.
Total resulsts: 349182
Page 5186 of 34,919
ยซ previous page ยป next page
Filters