7.3

CVSS3.1

CVE-2025-48797 - Gimp: multiple heap buffer overflows in tga parser

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

πŸ“… Published: May 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2025-5198 - Stackrox: xss in stackrox

A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes β€œRole” object* that is applied to a secured cluster. This obj…

πŸ“… Published: May 26, 2025, midnight πŸ”„ Last Modified: Feb. 27, 2026, 4:41 p.m.

7.3

CVSS3.1

CVE-2025-48796 - Gimp: stack-based buffer overflows in file-ico

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.

πŸ“… Published: May 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-2146 -

Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/…

πŸ“… Published: May 25, 2025, 11:36 p.m. πŸ”„ Last Modified: June 3, 2025, 3:49 p.m.

5.3

CVSS4.0

CVE-2025-5159 - H3C SecCenter SMP-E1114P02 download path traversal

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been rated as problematic. This issue affects the function Download of the file /cfgFile/1/download. The manipulation of the argument Name leads to path traversal. The attack may be initiated remotely. The exploit has be…

πŸ“… Published: May 25, 2025, 11:31 p.m. πŸ”„ Last Modified: June 3, 2025, 3:49 p.m.

5.3

CVSS4.0

CVE-2025-5158 - H3C SecCenter SMP-E1114P02 downloadSoftware path traversal

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been declared as problematic. This vulnerability affects the function downloadSoftware of the file /cfgFile/downloadSoftware. The manipulation of the argument filename leads to path traversal. The attack can be initiated…

πŸ“… Published: May 25, 2025, 11 p.m. πŸ”„ Last Modified: June 3, 2025, 3:49 p.m.

5.3

CVSS4.0

CVE-2025-5157 - H3C SecCenter SMP-E1114P02 fileContent path traversal

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects the function fileContent of the file /cfgFile/fileContent. The manipulation of the argument filePath leads to path traversal. It is possible to initiate the attack remotely. The …

πŸ“… Published: May 25, 2025, 10:31 p.m. πŸ”„ Last Modified: June 3, 2025, 3:49 p.m.

8.7

CVSS4.0

CVE-2025-5156 - H3C GR-5400AX aspForm EditWlanMacList buffer overflow

A vulnerability was found in H3C GR-5400AX up to 100R008 and classified as critical. Affected by this issue is the function EditWlanMacList of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack may be launched remotely. The exploit has been…

πŸ“… Published: May 25, 2025, 10 p.m. πŸ”„ Last Modified: June 3, 2025, 3:49 p.m.

5.3

CVSS4.0

CVE-2025-5155 - qianfox FoxCMS Article.php batchCope sql injection

A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical. Affected by this vulnerability is the function batchCope of the file app/admin/controller/Article.php. The manipulation of the argument ids leads to sql injection. The attack can be launched remotely. The exploit has…

πŸ“… Published: May 25, 2025, 7:31 p.m. πŸ”„ Last Modified: June 3, 2025, 3:49 p.m.

4.6

CVSS4.0

CVE-2025-5154 - PhonePe App SQLite Database databases cleartext storage in a file or on disk

A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. Local access is…

πŸ“… Published: May 25, 2025, 6:31 p.m. πŸ”„ Last Modified: June 3, 2025, 1:53 p.m.
Total resulsts: 349182
Page 5258 of 34,919
Β« previous page Β» next page
Filters