5.3

CVSS4.0

CVE-2025-3929 - Stored XSS vulnerability in MDaemon Email Server

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and acces…

πŸ“… Published: April 29, 2025, 11:36 a.m. πŸ”„ Last Modified: May 12, 2025, 7:35 p.m.

6.9

CVSS4.0

CVE-2025-4058 - Projectworlds Online Examination System Bloodgroop_process.php sql injection

A vulnerability classified as critical has been found in Projectworlds Online Examination System 1.0. This affects an unknown part of the file /Bloodgroop_process.php. The manipulation of the argument Pat_BloodGroup1 leads to sql injection. It is possible to initiate the attack remotely. The exploi…

πŸ“… Published: April 29, 2025, 11:31 a.m. πŸ”„ Last Modified: May 15, 2025, 8:44 p.m.

6.5

CVSS3.1

CVE-2025-1194 - Regular Expression Denial of Service (ReDoS) in huggingface/transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where regular expressions…

πŸ“… Published: April 29, 2025, 11:30 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 9:56 p.m.

7.5

CVSS3.1

CVE-2025-30194 - Denial of service via crafted DoH exchange

When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.9 version. A w…

πŸ“… Published: April 29, 2025, 11:25 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-46780 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

0.0

CVE-2025-46781 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

0.0

CVE-2025-46782 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

0.0

CVE-2025-46779 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

0.0

CVE-2025-46778 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

4.3

CVSS3.1

CVE-2025-3452 - SecuPress Free <= 2.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Ins…

The SecuPress Free β€” WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'secupress_reinstall_plugins_admin_ajax_cb' function in all versions up to, and including, 2.3.9. This makes it possible for authenticated attacke…

πŸ“… Published: April 29, 2025, 8:21 a.m. πŸ”„ Last Modified: April 20, 2026, 11:15 p.m.
Total resulsts: 346102
Page 5330 of 34,611
Β« previous page Β» next page
Filters