8.6

CVSS4.0

CVE-2025-3540 - H3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request getCapability FCGI_WizardPr…

A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this vulnerability is the function FCGI_WizardProtoProcess of the file /api/wizard/getCapability of the component HTTP POST Request Handler. The manipulation l…

📅 Published: April 13, 2025, 10:31 p.m. 🔄 Last Modified: April 15, 2025, 6:39 p.m.

8.1

CVSS3.1

CVE-2025-3445 - mholt/archiver: A Path Traversal "Zip Slip" vulnerability in mholt/archiver

A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing path traversal symlinks to create or overwrite files with the user's privileges or application utilizing the library. When using the archiver.Unarchi…

📅 Published: April 13, 2025, 10:10 p.m. 🔄 Last Modified: June 24, 2025, 9:44 a.m.

8.6

CVSS4.0

CVE-2025-3539 - H3C Magic BE18000 HTTP POST Request getBasicInfo FCGI_CheckStringIfContainsSemicolon command inject…

A vulnerability classified as critical has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getBasicInfo of the component HTTP POST Request Handler. The manip…

📅 Published: April 13, 2025, 10 p.m. 🔄 Last Modified: April 15, 2025, 6:39 p.m.

8.7

CVSS4.0

CVE-2025-3538 - D-Link DI-8100 jhttpd auth.asp auth_asp stack-based overflow

A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function auth_asp of the file /auth.asp of the component jhttpd. The manipulation of the argument callback leads to stack-based buffer overflow. The attack needs to be approached within the…

📅 Published: April 13, 2025, 6:31 p.m. 🔄 Last Modified: July 16, 2025, 3:36 p.m.

8.4

CVSS3.1

CVE-2024-56406 - Perl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytes

A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, including development versions from 5.33.1 through 5.41.10. When there are non-ASCII bytes in the left-hand-side of the `tr` operator, `S_do_trans_invmap` can overflow the destin…

📅 Published: April 13, 2025, 1:16 p.m. 🔄 Last Modified: Oct. 16, 2025, 2:15 p.m.

6.9

CVSS4.0

CVE-2025-3537 - Tutorials-Website Employee Management System update-user.php improper authorization

A vulnerability was found in Tutorials-Website Employee Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/update-user.php. The manipulation of the argument ID leads to improper authorization. It is possible to initiate the attack remotely. Th…

📅 Published: April 13, 2025, noon 🔄 Last Modified: June 5, 2025, 7:27 p.m.

5.4

CVSS3.1

CVE-2025-3423 - IBM Aspera Faspex 5 cross-site scripting

IBM Aspera Faspex 5.0.0 through 5.0.11 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

📅 Published: April 13, 2025, 11:56 a.m. 🔄 Last Modified: Sept. 1, 2025, 10:15 a.m.

6.9

CVSS4.0

CVE-2025-3536 - Tutorials-Website Employee Management System delete-user.php improper authorization

A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete-user.php. The manipulation of the argument ID leads to improper authorization. The attack may be launched remotely…

📅 Published: April 13, 2025, 11:31 a.m. 🔄 Last Modified: June 5, 2025, 7:26 p.m.

5.3

CVSS4.0

CVE-2025-3535 - shuanx BurpAPIFinder BurpApiFinder.db denial of service

A vulnerability has been found in shuanx BurpAPIFinder up to 2.0.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file BurpApiFinder.db. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed…

📅 Published: April 13, 2025, 11 a.m. 🔄 Last Modified: April 15, 2025, 6:39 p.m.

5.3

CVSS4.0

CVE-2025-3534 - PowerCreator CMS OpenPublicCourse.aspx sql injection

A vulnerability, which was classified as critical, was found in PowerCreator CMS 1.0. Affected is an unknown function of the file /OpenPublicCourse.aspx. The manipulation of the argument cid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the …

📅 Published: April 13, 2025, 10:31 a.m. 🔄 Last Modified: April 15, 2025, 6:39 p.m.
Total resulsts: 343944
Page 5375 of 34,395
« previous page » next page
Filters