7.8

CVSS3.1

CVE-2025-23105 -

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 6:08 p.m.

5.9

CVSS3.1

CVE-2024-40112 -

A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the "language" cookie to include arbitrary files from the server. This vulnerability can be exploited to disclose sensitive information.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: June 25, 2025, 7:29 p.m.

6.5

CVSS3.1

CVE-2025-27953 -

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 5:52 p.m.

3.1

CVSS3.1

CVE-2025-49112 - valkey: Valkey Integer Underflow Vulnerability

setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-44172 -

Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: June 3, 2025, 3:55 p.m.

6.7

CVSS3.1

CVE-2025-49163 -

Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2025-49113 - roundcubemail: Remote Code Execution in Roundcube via Unvalidated _from Parameter

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 23, 2026, 1:24 p.m.

6.1

CVSS3.1

CVE-2024-40114 -

A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie to inject malicious JavaScript code.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 12:59 a.m.

8.1

CVSS3.1

CVE-2024-57783 -

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-27955 -

Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 6 p.m.
Total resulsts: 349182
Page 5207 of 34,919
ยซ previous page ยป next page
Filters