0.0

CVE-2025-47300 -

Not used

📅 Published: May 5, 2025, 8:10 p.m. 🔄 Last Modified: May 6, 2025, 4:16 a.m.

0.0

CVE-2025-47301 -

Not used

📅 Published: May 5, 2025, 8:10 p.m. 🔄 Last Modified: May 6, 2025, 4:16 a.m.

0.0

CVE-2025-47302 -

Not used

📅 Published: May 5, 2025, 8:10 p.m. 🔄 Last Modified: May 6, 2025, 4:16 a.m.

5.8

CVSS3.1

CVE-2025-46813 - Private data leak on login-required Discourse sites

Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that some content on the site's homepage could be visible t…

📅 Published: May 5, 2025, 8:03 p.m. 🔄 Last Modified: Sept. 26, 2025, 12:54 p.m.

4.8

CVSS4.0

CVE-2025-4287 - PyTorch nccl.py torch.cuda.nccl.reduce denial of service

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been …

📅 Published: May 5, 2025, 8 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-46734 - league/commonmark Cross-site Scripting vulnerability in Attributes extension

league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The league/commonmark library provides configura…

📅 Published: May 5, 2025, 7:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-1909 - BuddyBoss Platform Pro <= 2.7.01 - Authentication Bypass via Apple OAuth provider

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthentic…

📅 Published: May 5, 2025, 7:42 p.m. 🔄 Last Modified: April 21, 2026, 9 p.m.

7.3

CVSS4.0

CVE-2025-46731 - Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work.…

📅 Published: May 5, 2025, 7:35 p.m. 🔄 Last Modified: Sept. 3, 2025, 6:06 p.m.

6.8

CVSS3.1

CVE-2025-46730 - Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit teams, and external ve…

📅 Published: May 5, 2025, 7:32 p.m. 🔄 Last Modified: Sept. 3, 2025, 6:18 p.m.

5.1

CVSS4.0

CVE-2025-4286 - Intelbras InControl Dispositivos Edição Page credentials storage

A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos Edição Page. The manipulation of the argument Senha de Comunicação leads to unprotected storage of credentials. It is possible to laun…

📅 Published: May 5, 2025, 7:31 p.m. 🔄 Last Modified: Aug. 20, 2025, 2:29 a.m.
Total resulsts: 349182
Page 5548 of 34,919
« previous page » next page
Filters