6.5

CVSS3.1

CVE-2024-40120 -

seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 2:09 p.m.

10

CVSS3.1

CVE-2025-47916 -

Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenti…

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: June 20, 2025, 5:42 p.m.

8.2

CVSS3.1

CVE-2025-47809 -

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center …

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-37890 - net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc As described in Gerrard's report [1], we have a UAF case when an hfsc class has a netem child qdisc. The crux of the issue is that hfsc is assuming that …

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 5:11 p.m.

4.5

CVSS3.1

CVE-2025-48174 -

In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

2.9

CVSS3.1

CVE-2025-48188 -

libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: July 17, 2025, 8:33 p.m.

5.3

CVSS4.0

CVE-2025-4729 - TOTOLINK A3002R/A3002RU HTTP POST Request formMapDelDevice command injection

A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads …

πŸ“… Published: May 15, 2025, 11:31 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

5.3

CVSS4.0

CVE-2025-47930 - Zulip Server has access control bypass for restrictions on creation of specific channel types

Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A similar technique work…

πŸ“… Published: May 15, 2025, 11:17 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 2:26 a.m.

6.9

CVSS4.0

CVE-2025-4728 - SourceCodester Best Online News Portal search.php sql injection

A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /search.php. The manipulation of the argument searchtitle leads to sql injection. It is possible to launch the attack remotely. The exploit has be…

πŸ“… Published: May 15, 2025, 11 p.m. πŸ”„ Last Modified: May 27, 2025, 7:51 p.m.

6.3

CVSS4.0

CVE-2025-4727 - Meteor livedata_server.js Object.assign redos

A vulnerability was found in Meteor up to 3.2.1 and classified as problematic. This issue affects the function Object.assign of the file packages/ddp-server/livedata_server.js. The manipulation of the argument forwardedFor leads to inefficient regular expression complexity. The attack may be initia…

πŸ“… Published: May 15, 2025, 11 p.m. πŸ”„ Last Modified: June 23, 2025, 3:14 p.m.
Total resulsts: 349182
Page 5377 of 34,919
Β« previous page Β» next page
Filters