8.1

CVSS3.1

CVE-2025-43715 -

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition.…

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:31 p.m.

7.6

CVSS3.1

CVE-2025-29461 -

An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 6:57 p.m.

7.2

CVSS3.1

CVE-2025-29181 -

FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 6:21 p.m.

8.8

CVSS3.1

CVE-2025-1568 -

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines…

πŸ“… Published: April 16, 2025, 11:06 p.m. πŸ”„ Last Modified: July 8, 2025, 6:07 p.m.

8.8

CVSS3.1

CVE-2025-2073 -

Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure

πŸ“… Published: April 16, 2025, 11:06 p.m. πŸ”„ Last Modified: July 11, 2025, 2:04 p.m.

6.5

CVSS3.1

CVE-2025-1704 -

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.

πŸ“… Published: April 16, 2025, 11:06 p.m. πŸ”„ Last Modified: July 11, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2025-1566 -

DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.

πŸ“… Published: April 16, 2025, 11:06 p.m. πŸ”„ Last Modified: July 8, 2025, 6:08 p.m.

6.8

CVSS3.1

CVE-2025-24907 - Hitachi Vantara Pentaho Data Integration & Analytics – Path Traversal

Overview Β  The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35) Β  Descriptio…

πŸ“… Published: April 16, 2025, 10:39 p.m. πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

4.9

CVSS3.1

CVE-2025-24911 - Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Ref…

Overview Β  XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back i…

πŸ“… Published: April 16, 2025, 10:35 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

4.9

CVSS3.1

CVE-2025-24910 - Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Ref…

Overview Β  XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back i…

πŸ“… Published: April 16, 2025, 10:32 p.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.
Total resulsts: 343975
Page 5238 of 34,398
Β« previous page Β» next page
Filters