3.3

CVSS3.1

CVE-2021-47671 - can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path

In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the function directly returns without calling netif_rx(skb). This means that the skb previously allocated by a…

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:15 a.m.

6.1

CVSS3.1

CVE-2025-29015 -

Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 6:30 p.m.

7.5

CVSS3.1

CVE-2025-25454 -

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:41 p.m.

6.5

CVSS3.1

CVE-2025-29449 -

An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 25, 2025, 4:28 p.m.

7.6

CVSS3.1

CVE-2025-29457 -

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 24, 2025, 2:13 p.m.

8.1

CVSS3.1

CVE-2025-43715 -

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition.…

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2025-29461 -

An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 6:57 p.m.

7.2

CVSS3.1

CVE-2025-29181 -

FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 6:21 p.m.

8.8

CVSS3.1

CVE-2025-1568 -

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines…

πŸ“… Published: April 16, 2025, 11:06 p.m. πŸ”„ Last Modified: July 8, 2025, 6:07 p.m.

8.8

CVSS3.1

CVE-2025-2073 -

Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure

πŸ“… Published: April 16, 2025, 11:06 p.m. πŸ”„ Last Modified: July 11, 2025, 2:04 p.m.
Total resulsts: 346551
Page 5495 of 34,656
Β« previous page Β» next page
Filters