9.8

CVSS3.1

CVE-2025-27832 - Ghostscript: NPDL device: Compression buffer overflow

An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

7.5

CVSS3.1

CVE-2024-44903 -

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.

πŸ“… Published: March 25, 2025, midnight πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

3.3

CVSS3.1

CVE-2025-2720 - libgsf: GNOME libgsf gsf_base64_encode_simple uninitialized variable

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: According to the code maintainer the call of the POC is invalid because the buffer pointed to by "data" must have "…

πŸ“… Published: March 24, 2025, 11:31 p.m. πŸ”„ Last Modified: March 27, 2025, 6:15 a.m.

5.1

CVSS4.0

CVE-2025-2717 - D-Link DIR-823X HTTP POST Request diag_nslookup sub_41710C os command injection

A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of the component HTTP POST Request Handler. The manipulation of the argument target_addr leads to os command injection. Th…

πŸ“… Published: March 24, 2025, 11:31 p.m. πŸ”„ Last Modified: May 21, 2025, 4:51 p.m.

8.8

CVSS3.1

CVE-2025-24514 - ingress-nginx controller - configuration injection via unsanitized auth-url annotation

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets …

πŸ“… Published: March 24, 2025, 11:29 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

4.8

CVSS3.1

CVE-2025-24513 - ingress-nginx controller - auth secret file path traversal vulnerability

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or…

πŸ“… Published: March 24, 2025, 11:29 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:18 p.m.

8.8

CVSS3.1

CVE-2025-1098 - ingress-nginx controller - configuration injection via unsanitized mirror annotations

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx cont…

πŸ“… Published: March 24, 2025, 11:29 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

8.8

CVSS3.1

CVE-2025-1097 - ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of…

πŸ“… Published: March 24, 2025, 11:29 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

9.8

CVSS3.1

CVE-2025-1974 - ingress-nginx admission controller RCE escalation

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note th…

πŸ“… Published: March 24, 2025, 11:28 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

5.1

CVSS4.0

CVE-2025-2716 - China Mobile P22g-CIac Samba Path path traversal

A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unknown code of the component Samba Path Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may…

πŸ“… Published: March 24, 2025, 11 p.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.
Total resulsts: 343996
Page 5712 of 34,400
Β« previous page Β» next page
Filters