5.3

CVSS4.0

CVE-2025-2752 - Open Asset Import Library Assimp CSM File fast_atof.h fast_atoreal_move out-of-bounds

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated…

📅 Published: March 25, 2025, 8 a.m. 🔄 Last Modified: July 17, 2025, 9:50 p.m.

5.3

CVSS4.0

CVE-2025-2751 - Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na lead…

📅 Published: March 25, 2025, 7:31 a.m. 🔄 Last Modified: July 17, 2025, 9:51 p.m.

5.3

CVSS4.0

CVE-2025-2750 - Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds write

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is p…

📅 Published: March 25, 2025, 7:31 a.m. 🔄 Last Modified: July 17, 2025, 9:51 p.m.

6.4

CVSS3.1

CVE-2024-12623 - DICOM Support <= 0.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in all versions up to, and including, 0.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker…

📅 Published: March 25, 2025, 7:04 a.m. 🔄 Last Modified: April 8, 2026, 5:26 p.m.

4.3

CVSS3.1

CVE-2025-1320 - teachPress <= 9.0.9 - Cross-Site Request Forgery to Import Delete

The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or incorrect nonce validation on the import.php page. This makes it possible for unauthenticated attackers to delete imports via a forged request grant…

📅 Published: March 25, 2025, 7:04 a.m. 🔄 Last Modified: April 8, 2026, 7:23 p.m.

5.3

CVSS3.1

CVE-2025-2252 - Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticate…

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated attackers to extr…

📅 Published: March 25, 2025, 7:04 a.m. 🔄 Last Modified: April 8, 2026, 5:11 p.m.

5.3

CVSS4.0

CVE-2025-2744 - zhijiantianya ruoyi-vue-pro Material Upload Interface upload-news-image path traversal

A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. It is po…

📅 Published: March 25, 2025, 7 a.m. 🔄 Last Modified: July 14, 2025, 8:11 p.m.

5.3

CVSS4.0

CVE-2025-2743 - zhijiantianya ruoyi-vue-pro Material Upload Interface upload-temporary path traversal

A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the file /admin-api/mp/material/upload-temporary of the component Material Upload Interface. The manipulation of the argument File leads to path t…

📅 Published: March 25, 2025, 7 a.m. 🔄 Last Modified: Aug. 25, 2025, 2:13 a.m.

5.3

CVSS4.0

CVE-2025-2742 - zhijiantianya ruoyi-vue-pro Material Upload Interface upload-permanent path traversal

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. The attack ca…

📅 Published: March 25, 2025, 6:31 a.m. 🔄 Last Modified: July 15, 2025, 1:07 p.m.

6.9

CVSS4.0

CVE-2025-2740 - PHPGurukul Old Age Home Management System eligibility.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/eligibility.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit ha…

📅 Published: March 25, 2025, 6:31 a.m. 🔄 Last Modified: April 1, 2025, 4:45 p.m.
Total resulsts: 343761
Page 5679 of 34,377
« previous page » next page
Filters