8.1

CVSS3.1

CVE-2025-32409 -

Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurr…

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 8, 2025, 6:13 p.m.

9.8

CVSS3.1

CVE-2025-28408 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 7 p.m.

5.4

CVSS3.1

CVE-2024-46494 -

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 12:33 p.m.

4.0

CVSS3.1

CVE-2025-29479 - hiredis: Heap Buffer Overflow in Hiredis

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 12, 2025, 5:15 p.m.

9.8

CVSS3.1

CVE-2025-28412 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:41 p.m.

9.8

CVSS3.1

CVE-2025-28402 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 5:17 p.m.

3.2

CVSS3.1

CVE-2025-29087 - sqlite: Integer Overflow in SQLite concat_ws Function

In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of …

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 12:43 p.m.

3.7

CVSS3.1

CVE-2025-3360 - Glibc: glib prior to 2.82.5 is vulnerable to integer overflow and buffer under-read when parsing a…

A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 7:16 a.m.

6.7

CVSS3.1

CVE-2025-28401 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 5:19 p.m.

7.2

CVSS3.1

CVE-2025-28403 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 4:48 p.m.
Total resulsts: 344064
Page 5485 of 34,407
Β« previous page Β» next page
Filters