8.8

CVSS3.0

CVE-2025-1048 - Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability

Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exis…

πŸ“… Published: April 23, 2025, 4:44 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 2:40 p.m.

7.8

CVSS3.0

CVE-2025-1047 - Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability

Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must v…

πŸ“… Published: April 23, 2025, 4:44 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 6:25 p.m.

7.8

CVSS3.0

CVE-2025-1046 - Luxion KeyShot SKP File Parsing Use-After-Free Remote Code Execution Vulnerability

Luxion KeyShot SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious …

πŸ“… Published: April 23, 2025, 4:43 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 6:25 p.m.

7.8

CVSS3.0

CVE-2025-1045 - Luxion KeyShot Viewer KSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabili…

Luxion KeyShot Viewer KSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot Viewer. User interaction is required to exploit this vulnerability in that the targ…

πŸ“… Published: April 23, 2025, 4:42 p.m. πŸ”„ Last Modified: Aug. 7, 2025, 6:26 p.m.

6.5

CVSS3.1

CVE-2024-47829 - pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect p…

pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_…

πŸ“… Published: April 23, 2025, 3:42 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 8:08 p.m.

7.5

CVSS3.1

CVE-2025-21605 - Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client

Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can cause unlimited growth of output buffers, until the server runs out of memory or is killed. By default, the Redis configuration does not limit the output …

πŸ“… Published: April 23, 2025, 3:38 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 6:16 p.m.

9.3

CVSS4.0

CVE-2025-32969 - org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API

XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQL statements on the database backend, includ…

πŸ“… Published: April 23, 2025, 3:33 p.m. πŸ”„ Last Modified: April 30, 2025, 3:50 p.m.

8.6

CVSS4.0

CVE-2025-32968 - org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests throug…

XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it is possible for a user with SCRIPT right to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQL statements on the database backend. De…

πŸ“… Published: April 23, 2025, 3:27 p.m. πŸ”„ Last Modified: April 30, 2025, 4:09 p.m.

8.2

CVSS4.0

CVE-2025-32966 - Dataease H2 JDBC Connection Remote Code Execution

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.

πŸ“… Published: April 23, 2025, 3:21 p.m. πŸ”„ Last Modified: June 24, 2025, 4:36 p.m.

0.0

CVE-2025-3896 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: April 23, 2025, 2:30 p.m. πŸ”„ Last Modified: July 5, 2025, 11:15 p.m.
Total resulsts: 349182
Page 5688 of 34,919
Β« previous page Β» next page
Filters