8.6

CVSS4.0

CVE-2025-36521 - MicroDicom DICOM Viewer Out-of-bounds Read

MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must open a malicious DCM file for exploitation.

πŸ“… Published: May 1, 2025, 6:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-3517 -

Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username.

πŸ“… Published: May 1, 2025, 6:26 p.m. πŸ”„ Last Modified: June 17, 2025, 2:18 p.m.

8.6

CVSS4.0

CVE-2025-35975 - MicroDicom DICOM Viewer Out-of-bounds Write

MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. The user must open a malicious DCM file for exploitation.

πŸ“… Published: May 1, 2025, 6:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2025-46568 - Stirling-PDF Server-Side Request Forgery (SSRF)-Induced Arbitrary File Read Vulnerability

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is vulnerable to SSRF-induced arbitrary file read. WeasyPrint redefines a set of HTML tags, including img, embed, object, and others. The references to …

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: Feb. 6, 2026, 8:16 p.m.

6.1

CVSS3.1

CVE-2025-46567 - LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files from an input direct…

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: June 17, 2025, 2:19 p.m.

6.8

CVSS4.0

CVE-2025-46566 - Dataease redshift JDBC Connection Remote Code Execution

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.9.

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: May 28, 2025, 4:02 p.m.

6

CVSS4.0

CVE-2025-46565 - Vite's server.fs.deny bypassed with /. for files under project root

Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (usin…

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 3:40 p.m.

6.9

CVSS4.0

CVE-2025-46345 - Auth0 Account Link Extension JWT Invalid Signature Validation

Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization. This issue h…

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-46337 - SQL injection in ADOdb PostgreSQL driver pg_insert_id() method

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and c…

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-4173 - SourceCodester Online Eyewear Shop Master.php delete_cart sql injection

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_cart of the file /oews/classes/Master.php?f=delete_cart. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely.…

πŸ“… Published: May 1, 2025, 5 p.m. πŸ”„ Last Modified: May 13, 2025, 8:27 p.m.
Total resulsts: 347837
Page 5450 of 34,784
Β« previous page Β» next page
Filters