6.5

CVSS3.1

CVE-2025-30673 - Sub::HandlesVia for Perl allows untrusted code to be included from the current working directory

Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may beย loaded instead of the intended file, potentially leading to arbitraryย codโ€ฆ

๐Ÿ“… Published: April 1, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:26 p.m.

6.5

CVSS3.1

CVE-2025-30672 - Mite for Perl generates code with an untrusted search path vulnerability

Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execโ€ฆ

๐Ÿ“… Published: April 1, 2025, 1:51 a.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:26 p.m.

8.3

CVSS3.1

CVE-2025-21384 - Azure Health Bot Elevation of Privilege Vulnerability

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

๐Ÿ“… Published: April 1, 2025, 12:40 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.

5.3

CVSS4.0

CVE-2025-3045 - oretnom23/SourceCodester Apartment Visitor Management System remove-apartment.php sql injection

A vulnerability, which was classified as critical, was found in oretnom23/SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /remove-apartment.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remoteโ€ฆ

๐Ÿ“… Published: April 1, 2025, 12:31 a.m. ๐Ÿ”„ Last Modified: May 27, 2025, 6:53 p.m.

6.9

CVSS4.0

CVE-2025-3043 - GuoMinJim PersonManage login preHandle path traversal

A vulnerability, which was classified as critical, has been found in GuoMinJim PersonManage 1.0. This issue affects the function preHandle of the file /login/. The manipulation of the argument Request leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to tโ€ฆ

๐Ÿ“… Published: April 1, 2025, 12:31 a.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:26 p.m.

5.3

CVSS4.0

CVE-2025-3042 - Project Worlds Online Time Table Generator updateprofile.php unrestricted upload

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability affects unknown code of the file /student/updateprofile.php. The manipulation of the argument pic leads to unrestricted upload. The attack can be initiated remotely. The exploit haโ€ฆ

๐Ÿ“… Published: April 1, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 3:38 p.m.

8.1

CVSS3.1

CVE-2025-21947 - ksmbd: fix type confusion via race condition when using ipc_msg_send_request

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix type confusion via race condition when using ipc_msg_send_request req->handle is allocated using ksmbd_acquire_id(&ipc_ida), based on ida_alloc. req->handle from ksmbd_ipc_login_request and FSCTL_PIPE_TRANSCEIVE ioctl โ€ฆ

๐Ÿ“… Published: April 1, 2025, midnight ๐Ÿ”„ Last Modified: April 2, 2026, 8:39 a.m.

5.5

CVSS3.1

CVE-2025-21944 - ksmbd: fix bug on trap in smb2_lock

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix bug on trap in smb2_lock If lock count is greater than 1, flags could be old value. It should be checked with flags of smb_lock, not flags. It will cause bug-on trap from locks_free_lock in error handling routine.

๐Ÿ“… Published: April 1, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.8

CVSS3.1

CVE-2025-21969 - Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd After the hci sync command releases l2cap_conn, the hci receive data work queue references the released l2cap_conn when sending to the upper layer. Add hci dev lockโ€ฆ

๐Ÿ“… Published: April 1, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 3:28 p.m.

7.8

CVSS3.1

CVE-2025-21983 - mm/slab/kvfree_rcu: Switch to WQ_MEM_RECLAIM wq

In the Linux kernel, the following vulnerability has been resolved: mm/slab/kvfree_rcu: Switch to WQ_MEM_RECLAIM wq Currently kvfree_rcu() APIs use a system workqueue which is "system_unbound_wq" to driver RCU machinery to reclaim a memory. Recently, it has been noted that the following kernel wโ€ฆ

๐Ÿ“… Published: April 1, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 30, 2025, 7:14 p.m.
Total resulsts: 343887
Page 5559 of 34,389
ยซ previous page ยป next page
Filters