8.5

CVSS4.0

CVE-2025-35996 - KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the…

πŸ“… Published: May 1, 2025, 6:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-32011 - KUNBUS Revolution Pi Authentication Bypass by Primary Weakness

KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal.

πŸ“… Published: May 1, 2025, 6:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-24522 - KUNBUS Revolution Pi Authentication Bypass by Primary Weakness

KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.

πŸ“… Published: May 1, 2025, 6:37 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-36521 - MicroDicom DICOM Viewer Out-of-bounds Read

MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must open a malicious DCM file for exploitation.

πŸ“… Published: May 1, 2025, 6:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-3517 -

Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username.

πŸ“… Published: May 1, 2025, 6:26 p.m. πŸ”„ Last Modified: June 17, 2025, 2:18 p.m.

8.6

CVSS4.0

CVE-2025-35975 - MicroDicom DICOM Viewer Out-of-bounds Write

MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. The user must open a malicious DCM file for exploitation.

πŸ“… Published: May 1, 2025, 6:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2025-46568 - Stirling-PDF Server-Side Request Forgery (SSRF)-Induced Arbitrary File Read Vulnerability

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is vulnerable to SSRF-induced arbitrary file read. WeasyPrint redefines a set of HTML tags, including img, embed, object, and others. The references to …

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: Feb. 6, 2026, 8:16 p.m.

6.1

CVSS3.1

CVE-2025-46567 - LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files from an input direct…

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: June 17, 2025, 2:19 p.m.

6.8

CVSS4.0

CVE-2025-46566 - Dataease redshift JDBC Connection Remote Code Execution

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.9.

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: May 28, 2025, 4:02 p.m.

6

CVSS4.0

CVE-2025-46565 - Vite's server.fs.deny bypassed with /. for files under project root

Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (usin…

πŸ“… Published: May 1, 2025, 5:20 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 3:40 p.m.
Total resulsts: 348200
Page 5486 of 34,820
Β« previous page Β» next page
Filters