7.1

CVSS3.1

CVE-2025-0468 - GPU DDK - ui64RobustnessAddress can overwrite Freelist / HWRT (and bypass PMMETA)

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kerne…

πŸ“… Published: April 4, 2025, 3:39 p.m. πŸ”„ Last Modified: April 7, 2025, 3:15 p.m.

5.1

CVSS4.0

CVE-2025-3253 - xujiangfei admintwo insertTree cross site scripting

A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown processing of the file /ztree/insertTree. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to …

πŸ“… Published: April 4, 2025, 3:31 p.m. πŸ”„ Last Modified: April 23, 2025, 2:40 p.m.

5.1

CVSS4.0

CVE-2025-3252 - xujiangfei admintwo add cross site scripting

A vulnerability has been found in xujiangfei admintwo 1.0 and classified as problematic. This vulnerability affects unknown code of the file /resource/add. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to th…

πŸ“… Published: April 4, 2025, 3:31 p.m. πŸ”„ Last Modified: April 23, 2025, 2:45 p.m.

0.0

CVE-2025-3283 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: April 4, 2025, 3:30 p.m. πŸ”„ Last Modified: July 5, 2025, 11:15 p.m.

5.1

CVSS4.0

CVE-2025-3251 - xujiangfei admintwo updateSet cross site scripting

A vulnerability, which was classified as problematic, was found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation of the argument motto leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed …

πŸ“… Published: April 4, 2025, 3 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 2:38 p.m.

5.3

CVSS4.0

CVE-2025-3250 - elunez eladmin Maintenance Management Module testConnect deserialization

A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of the file /api/database/testConnect of the component Maintenance Management Module. The manipulation leads to deserialization. The attack may be launche…

πŸ“… Published: April 4, 2025, 3 p.m. πŸ”„ Last Modified: May 15, 2025, 8:44 p.m.

9.1

CVSS3.1

CVE-2025-31480 - aiven-extras allows PostgreSQL Privilege Escalation through format function

aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being schema-prefixed. Affected users should install 1.1.16 and en…

πŸ“… Published: April 4, 2025, 2:49 p.m. πŸ”„ Last Modified: April 7, 2025, 2:18 p.m.

6.8

CVSS3.1

CVE-2025-31130 - gitoxide does not detect SHA-1 collision attacks

gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations f…

πŸ“… Published: April 4, 2025, 2:41 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 6:16 p.m.

9.8

CVSS3.1

CVE-2025-27520 - BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability caused by insecure deserialization has been identified in the latest version (v1.4.2) of BentoML. It allows any unauthenticated user to execute arbi…

πŸ“… Published: April 4, 2025, 2:28 p.m. πŸ”„ Last Modified: June 27, 2025, 12:48 p.m.

5.3

CVSS4.0

CVE-2025-3249 - TOTOLINK A6000R mtkwifi.lua apcli_cancel_wps command injection

A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The explo…

πŸ“… Published: April 4, 2025, 2 p.m. πŸ”„ Last Modified: May 28, 2025, 3:15 p.m.
Total resulsts: 343968
Page 5497 of 34,397
Β« previous page Β» next page
Filters