7.5

CVSS3.1

CVE-2025-54581 - vproxy is vulnerable to a divide by zero DoS attack

vproxy is an HTTP/HTTPS/SOCKS5 proxy server. In versions 2.3.3 and below, untrusted data is extracted from the user-controlled HTTP Proxy-Authorization header and passed to Extension::try_from and flows into parse_ttl_extension where it is parsed as a TTL value. If an attacker supplies a TTL of zer…

πŸ“… Published: July 30, 2025, 7:57 p.m. πŸ”„ Last Modified: July 31, 2025, 6:42 p.m.

5.3

CVSS3.1

CVE-2025-54575 - ImageSharp Triggers an Infinite Loop in its GIF Decoder When Skipping Malformed Comment Extension B…

ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. Th…

πŸ“… Published: July 30, 2025, 7:55 p.m. πŸ”„ Last Modified: July 31, 2025, 6:42 p.m.

9.1

CVSS3.1

CVE-2025-54576 - OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter incl…

OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy deployments are vulnerable when using the skip_auth_routes configuration option …

πŸ“… Published: July 30, 2025, 7:41 p.m. πŸ”„ Last Modified: July 31, 2025, 6:42 p.m.

6.9

CVSS4.0

CVE-2025-8330 - code-projects Vehicle Management edit1.php sql injection

A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit1.php. The manipulation of the argument sno leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…

πŸ“… Published: July 30, 2025, 7:32 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 8:48 p.m.

6.9

CVSS4.0

CVE-2025-8329 - code-projects Vehicle Management filter3.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /filter3.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclose…

πŸ“… Published: July 30, 2025, 7:02 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 8:48 p.m.

5.5

CVSS3.1

CVE-2025-30103 -

Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

πŸ“… Published: July 30, 2025, 6:18 p.m. πŸ”„ Last Modified: July 31, 2025, 6:42 p.m.

2.5

CVSS3.1

CVE-2025-36609 -

Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: July 30, 2025, 6:14 p.m. πŸ”„ Last Modified: July 31, 2025, 6:42 p.m.

6.5

CVSS3.1

CVE-2025-36608 -

Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

πŸ“… Published: July 30, 2025, 6:09 p.m. πŸ”„ Last Modified: July 31, 2025, 6:42 p.m.

6.9

CVSS4.0

CVE-2025-8328 - code-projects Exam Form Submission register.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument USN leads to sql injection. The attack may be launched remotely. The exploit …

πŸ“… Published: July 30, 2025, 6:02 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 8:48 p.m.

6.5

CVSS3.1

CVE-2025-30480 -

Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerProtect Data Manager. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.

πŸ“… Published: July 30, 2025, 6:01 p.m. πŸ”„ Last Modified: July 31, 2025, 6:42 p.m.
Total resulsts: 304277
Page 54 of 30,428
Β« previous page Β» next page
Filters