6.1

CVSS3.1

CVE-2025-29686 -

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /inform/InformManageController.java.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 7:59 p.m.

9.1

CVSS3.1

CVE-2025-27891 -

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds reads via malformed NAS packets.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: July 1, 2025, 3 p.m.

6.5

CVSS3.1

CVE-2025-26784 -

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: June 25, 2025, 3:11 p.m.

7.5

CVSS3.1

CVE-2025-26783 -

An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, W1000, Modem 5300, and Modem 5400. Incorrect handling of undefined values leads to a Denial of Service.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: July 1, 2025, 3 p.m.

4.6

CVSS3.1

CVE-2025-25370 -

An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive information via the show app only setting function.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2023-53146 - media: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer()

In the Linux kernel, the following vulnerability has been resolved: media: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer() In dw2102_i2c_transfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally rea…

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:18 a.m.

8.8

CVSS3.1

CVE-2024-54780 -

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arb…

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 1:03 p.m.

5.4

CVSS3.1

CVE-2024-54779 -

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 2:51 p.m.

7.5

CVSS3.1

CVE-2025-44879 -

WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-29689 -

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java.

πŸ“… Published: May 14, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 7:59 p.m.
Total resulsts: 349182
Page 5417 of 34,919
Β« previous page Β» next page
Filters