9.8

CVSS3.1

CVE-2025-46191 -

Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attack…

πŸ“… Published: May 9, 2025, midnight πŸ”„ Last Modified: May 22, 2025, 6:52 p.m.

9.1

CVSS3.1

CVE-2025-45887 -

Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.

πŸ“… Published: May 9, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:39 p.m.

6.8

CVSS3.1

CVE-2025-28201 -

An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.

πŸ“… Published: May 9, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:31 p.m.

5.5

CVSS3.1

CVE-2025-37859 - page_pool: avoid infinite loop to schedule delayed worker

In the Linux kernel, the following vulnerability has been resolved: page_pool: avoid infinite loop to schedule delayed worker We noticed the kworker in page_pool_release_retry() was waken up repeatedly and infinitely in production because of the buggy driver causing the inflight less than 0 and w…

πŸ“… Published: May 9, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 8:10 p.m.

9.8

CVSS3.1

CVE-2025-46193 -

SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.

πŸ“… Published: May 9, 2025, midnight πŸ”„ Last Modified: May 22, 2025, 6:49 p.m.

5.9

CVSS3.1

CVE-2025-4382 - Grub2: grub allow access to encrypted device through cli once root device is unlocked via tpm

A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. If an attacker with physical access can corrupt the underlying…

πŸ“… Published: May 8, 2025, 11:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-4443 - D-Link DIR-605L sub_454F2C command injection

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be initiated remotely. The vendor was contacted early about this disclosure. This vulne…

πŸ“… Published: May 8, 2025, 11:31 p.m. πŸ”„ Last Modified: May 13, 2025, 8:23 p.m.

8.7

CVSS4.0

CVE-2025-4442 - D-Link DIR-605L formSetWAN_Wizard55 buffer overflow

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetWAN_Wizard55. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The vendor was contacted early about this dis…

πŸ“… Published: May 8, 2025, 11:31 p.m. πŸ”„ Last Modified: May 13, 2025, 8:23 p.m.

8.7

CVSS4.0

CVE-2025-4441 - D-Link DIR-605L formSetWAN_Wizard534 buffer overflow

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formSetWAN_Wizard534. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disc…

πŸ“… Published: May 8, 2025, 11 p.m. πŸ”„ Last Modified: May 13, 2025, 8:23 p.m.

8.6

CVSS4.0

CVE-2025-4440 - H3C GR-1800AX aspForm EnableIpv6 buffer overflow

A vulnerability was found in H3C GR-1800AX up to 100R008 and classified as critical. Affected by this issue is the function EnableIpv6 of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. Access to the local network is required for this attack to succeed. Th…

πŸ“… Published: May 8, 2025, 11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348132
Page 5382 of 34,814
Β« previous page Β» next page
Filters