2.9

CVSS3.1

CVE-2025-32415 - libxml2: Out-of-bounds Read in xmlSchemaIDCFillNodeTables

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

7.6

CVSS3.1

CVE-2025-29460 -

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 25, 2025, 4:27 p.m.

7.6

CVSS3.1

CVE-2025-29459 -

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: June 27, 2025, 3:45 p.m.

9.8

CVSS3.1

CVE-2025-29045 -

Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_text_0 key value

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 6:47 p.m.

7.2

CVSS3.1

CVE-2025-29180 -

In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 6:44 p.m.

5.4

CVSS3.1

CVE-2025-43717 -

In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-29454 -

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 4:27 p.m.

6.5

CVSS3.1

CVE-2025-29453 -

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 4:27 p.m.

7.2

CVSS3.1

CVE-2025-29661 -

Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 6:20 p.m.

6.5

CVSS3.1

CVE-2025-29456 -

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 4:27 p.m.
Total resulsts: 346554
Page 5493 of 34,656
ยซ previous page ยป next page
Filters