3.3

CVSS3.1

CVE-2025-48064 - GitHub Desktop vulnerable to maliciously crafted file renames leading to information disclosure

GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to access a network share…

📅 Published: May 21, 2025, 5:40 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-48063 - XWiki Platform Security Authorization Bridge allows users with just edit right can enforce required…

XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part of the security model of required rights is that a user who doesn't have a right also cannot define that right as required right. That way, users who are edit…

📅 Published: May 21, 2025, 5:38 p.m. 🔄 Last Modified: June 24, 2025, 9:44 a.m.

7.7

CVSS4.0

CVE-2025-48060 - AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)

jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz);`. As of time of publication, no patched versions…

📅 Published: May 21, 2025, 5:32 p.m. 🔄 Last Modified: Nov. 3, 2025, 7:16 p.m.

5.3

CVSS4.0

CVE-2025-5033 - XiaoBingby TeaCMS addUser cross-site request forgery

A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/me/teacms/controller/admin/UserManageController/addUser. The manipulation leads to cross-site request forgery. The attack can be launc…

📅 Published: May 21, 2025, 5:31 p.m. 🔄 Last Modified: June 20, 2025, 4:15 p.m.

4.6

CVSS4.0

CVE-2025-47291 - containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespac…

containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes limits are not honor…

📅 Published: May 21, 2025, 5:26 p.m. 🔄 Last Modified: Sept. 19, 2025, 5:25 p.m.

7.7

CVSS4.0

CVE-2025-46822 - Unauthenticated Arbitrary File Read via Absolute Path

OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized acces…

📅 Published: May 21, 2025, 5:23 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS4.0

CVE-2025-2102 -

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.

📅 Published: May 21, 2025, 5:19 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-5020 - Links using non-HTTP schemes opened from other apps such as Safari could have allowed spoofing of w…

Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client. This vulnerability was fixed in Firefox for iOS 139.

📅 Published: May 21, 2025, 5:18 p.m. 🔄 Last Modified: April 20, 2026, 8:45 p.m.

5.9

CVSS4.0

CVE-2025-0372 -

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.

📅 Published: May 21, 2025, 5:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-5032 - Campcodes Online Shopping Portal edit-category.php sql injection

A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit has been d…

📅 Published: May 21, 2025, 5 p.m. 🔄 Last Modified: May 28, 2025, 2:12 p.m.
Total resulsts: 349182
Page 5297 of 34,919
« previous page » next page
Filters