4.3

CVSS3.1

CVE-2025-32357 -

In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.

πŸ“… Published: April 5, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 4:37 p.m.

4

CVSS3.1

CVE-2025-32364 - poppler: Floating-Point Exception in Poppler

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

πŸ“… Published: April 5, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

4

CVSS3.1

CVE-2025-32365 - poppler: Out-of-Bounds Read in Poppler

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

πŸ“… Published: April 5, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

4.8

CVSS3.1

CVE-2025-32359 -

In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end level, and not when…

πŸ“… Published: April 5, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 3:31 p.m.

4.8

CVSS3.1

CVE-2025-32352 -

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

πŸ“… Published: April 5, 2025, midnight πŸ”„ Last Modified: July 12, 2025, 4:01 p.m.

10

CVSS3.1

CVE-2021-47667 -

An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping off a file via a POST /dropoff request.

πŸ“… Published: April 5, 2025, midnight πŸ”„ Last Modified: July 12, 2025, 10:01 p.m.

4.8

CVSS3.1

CVE-2025-32366 -

In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=ntohs(rr->rdlen) and memcpy(response+offset,*end,*rdlen) without a check for whether the sum of *end and *rdlen exceeds max. Consequently, *rdlen may be larger than the amount of r…

πŸ“… Published: April 5, 2025, midnight πŸ”„ Last Modified: July 12, 2025, 4:01 p.m.

6.4

CVSS3.1

CVE-2025-2889 - Link Library <= 7.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Link Additiona…

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level ac…

πŸ“… Published: April 4, 2025, 11:22 p.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.

6.9

CVSS4.0

CVE-2025-3268 - qinguoyi TinyWebServer http_conn.cpp improper authentication

A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentication. The attack can be initiated remotely. The exploit has …

πŸ“… Published: April 4, 2025, 9 p.m. πŸ”„ Last Modified: April 23, 2025, 1:11 p.m.

3.7

CVSS3.1

CVE-2025-3416 - Rust-openssl: rust-openssl use-after-free in `md::fetch` and `cipher::fetch`

A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.

πŸ“… Published: April 4, 2025, 8:31 p.m. πŸ”„ Last Modified: Nov. 15, 2025, 4:21 a.m.
Total resulsts: 344032
Page 5489 of 34,404
Β« previous page Β» next page
Filters