2.9

CVSS3.1

CVE-2023-26819 - cJSON: cJSON rejects a valid text

cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.

πŸ“… Published: April 19, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

6.4

CVSS3.1

CVE-2025-43918 -

SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requester's email address, even when the requester does not otherwise establish administrative control of that domai…

πŸ“… Published: April 19, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

2.5

CVSS3.1

CVE-2022-47111 -

7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected.

πŸ“… Published: April 19, 2025, midnight πŸ”„ Last Modified: Aug. 18, 2025, 4:40 p.m.

2.5

CVSS3.1

CVE-2022-47112 -

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

πŸ“… Published: April 19, 2025, midnight πŸ”„ Last Modified: Aug. 18, 2025, 4:41 p.m.

8.2

CVSS3.1

CVE-2025-43917 -

In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file then is executed by a LaunchDaemon as root.

πŸ“… Published: April 19, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:31 p.m.

5.3

CVSS4.0

CVE-2025-3796 - PHPGurukul Men Salon Management System contact-us.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us.php. The manipulation of the argument pagetitle/pagedes/email/mobnumber/timing leads to sql injection. It is possible to initiate the attac…

πŸ“… Published: April 18, 2025, 9 p.m. πŸ”„ Last Modified: May 28, 2025, 3:51 p.m.

8.7

CVSS3.1

CVE-2025-32953 - z80pack Vulnerable to Exposure of the GITHUB_TOKEN in Workflow Run Artifact

z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubuntu.yml` workflow file uses `actions/upload-artifact@v4` to upload the `z80pack-ubuntu` artifact. This artifact is a zip of the current directory, which includes the automatically g…

πŸ“… Published: April 18, 2025, 8:42 p.m. πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.8

CVSS4.0

CVE-2025-3795 - DaiCuo SEO Optimization Settings Section cross site scripting

A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO Optimization Settings Section. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed …

πŸ“… Published: April 18, 2025, 8 p.m. πŸ”„ Last Modified: June 23, 2025, 7:49 p.m.

6.5

CVSS3.1

CVE-2025-32377 - Rasa Pro Missing Authentication For Voice Connector APIs

Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is configured in the credent…

πŸ“… Published: April 18, 2025, 7:59 p.m. πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.3

CVSS3.1

CVE-2025-36625 - Log Poisoning in Nessus

In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.

πŸ“… Published: April 18, 2025, 7:17 p.m. πŸ”„ Last Modified: July 12, 2025, 4:01 p.m.
Total resulsts: 343919
Page 5190 of 34,392
Β« previous page Β» next page
Filters