4.3

CVSS3.1

CVE-2025-27095 - JumpServer has a Kubernetes Token Leak Vulnerability

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged account can access the Kubernetes session feature and manipulate the kubeconfig file to redirect API requests to an external server controlโ€ฆ

๐Ÿ“… Published: March 31, 2025, 3:08 p.m. ๐Ÿ”„ Last Modified: Nov. 12, 2025, 3:50 p.m.

4.8

CVSS4.0

CVE-2025-3000 - PyTorch torch.jit.script memory corruption

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: March 31, 2025, 3 p.m. ๐Ÿ”„ Last Modified: May 29, 2025, 3:53 p.m.

4.5

CVSS3.1

CVE-2023-33302 -

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an authenticated attacker with regular webmaiโ€ฆ

๐Ÿ“… Published: March 31, 2025, 2:58 p.m. ๐Ÿ”„ Last Modified: July 23, 2025, 3:53 p.m.

4.8

CVSS4.0

CVE-2025-2999 - PyTorch torch.nn.utils.rnn.unpack_sequence memory corruption

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: March 31, 2025, 2:31 p.m. ๐Ÿ”„ Last Modified: May 29, 2025, 3:53 p.m.

8.5

CVSS4.0

CVE-2024-12021 - Stored Cross-Site Scripting

Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interfaces. The impact of exploitation may result in the compromise of local accounts managed by the Coverity platform as well as other standard impacts resulting from cross-site scriptโ€ฆ

๐Ÿ“… Published: March 31, 2025, 2 p.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:26 p.m.

4.8

CVSS4.0

CVE-2025-2998 - PyTorch torch.nn.utils.rnn.pad_packed_sequence memory corruption

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the pโ€ฆ

๐Ÿ“… Published: March 31, 2025, 2 p.m. ๐Ÿ”„ Last Modified: May 29, 2025, 3:53 p.m.

5.3

CVSS4.0

CVE-2025-2997 - zhangyanbo2007 youkefu url server-side request forgery

A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown function of the file /res/url. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been discloseโ€ฆ

๐Ÿ“… Published: March 31, 2025, 1:31 p.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 5:35 p.m.

7.5

CVSS3.1

CVE-2023-0881 - DDoS in Ubuntu package linux-bluefield

Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package.

๐Ÿ“… Published: March 31, 2025, 1:28 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 5:13 p.m.

6.9

CVSS4.0

CVE-2025-2996 - Tenda FH1202 Web Management Interface SysToolDDNS access control

A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. This issue affects some unknown processing of the file /goform/SysToolDDNS of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The expโ€ฆ

๐Ÿ“… Published: March 31, 2025, 1 p.m. ๐Ÿ”„ Last Modified: April 8, 2025, 1:04 p.m.

0.0

CVE-2025-31629 - WordPress Infusionsoft Web Form JavaScript plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerabiliโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Allred Infusionsoft Web Form JavaScript infusionsoft-web-form-javascript allows Stored XSS.This issue affects Infusionsoft Web Form JavaScript: from n/a through <= 1.1.1.

๐Ÿ“… Published: March 31, 2025, 12:55 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:21 p.m.
Total resulsts: 343975
Page 5601 of 34,398
ยซ previous page ยป next page
Filters