8.8

CVSS3.1

CVE-2025-4919 - Out-of-bounds access when optimizing linear sums

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.

πŸ“… Published: May 17, 2025, 9:07 p.m. πŸ”„ Last Modified: April 20, 2026, 5:15 p.m.

9.8

CVSS3.1

CVE-2025-4918 - Out-of-bounds access when resolving Promise objects

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.

πŸ“… Published: May 17, 2025, 9:07 p.m. πŸ”„ Last Modified: April 20, 2026, 5:15 p.m.

0.0

CVE-2025-4921 -

Duplicate ofΒ CVE-2025-4919

πŸ“… Published: May 17, 2025, 9:07 p.m. πŸ”„ Last Modified: May 18, 2025, 8:15 p.m.

0.0

CVE-2025-4920 -

Duplicate ofΒ CVE-2025-4918

πŸ“… Published: May 17, 2025, 9:07 p.m. πŸ”„ Last Modified: May 18, 2025, 8:15 p.m.

6.9

CVSS4.0

CVE-2025-4837 - projectworlds Student Project Allocation System make_group_sql.php sql injection

A vulnerability classified as critical has been found in projectworlds Student Project Allocation System 1.0. This affects an unknown part of the file /make_group_sql.php. The manipulation of the argument mem1/mem2/mem3 leads to sql injection. It is possible to initiate the attack remotely. The exp…

πŸ“… Published: May 17, 2025, 8:31 p.m. πŸ”„ Last Modified: May 28, 2025, 1:58 p.m.

6.9

CVSS4.0

CVE-2025-4836 - Projectworlds Life Insurance Management System deleteAgent.php sql injection

A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /deleteAgent.php. The manipulation of the argument agent_id leads to sql injection. The attack may be launched remotely. T…

πŸ“… Published: May 17, 2025, 8 p.m. πŸ”„ Last Modified: May 28, 2025, 1:54 p.m.

8.7

CVSS4.0

CVE-2025-4835 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWlanRedirect buffer overflow

A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of the argument redire…

πŸ“… Published: May 17, 2025, 7:31 p.m. πŸ”„ Last Modified: May 23, 2025, 3:50 p.m.

8.7

CVSS4.0

CVE-2025-4834 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSetLg buffer overflow

A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been classified as critical. Affected is an unknown function of the file /boafrm/formSetLg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. I…

πŸ“… Published: May 17, 2025, 7 p.m. πŸ”„ Last Modified: May 23, 2025, 3:50 p.m.

0.0

CVE-2024-13965 -

wrong year

πŸ“… Published: May 17, 2025, 6:44 p.m. πŸ”„ Last Modified: May 17, 2025, 8:15 p.m.

0.0

CVE-2024-13964 -

wrong year

πŸ“… Published: May 17, 2025, 6:44 p.m. πŸ”„ Last Modified: May 17, 2025, 8:15 p.m.
Total resulsts: 349182
Page 5356 of 34,919
Β« previous page Β» next page
Filters