9.8
CVE-2025-28413 -
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
8.1
CVE-2025-32409 -
Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrβ¦
8.8
CVE-2025-28407 -
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId
9.8
CVE-2025-28411 -
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
6.1
CVE-2025-29594 -
A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scriptiβ¦
5.5
CVE-2025-29480 - gdal: Buffer Overflow in GDAL
Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invalid and could not be reproduced.
9.8
CVE-2025-28405 -
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
6.7
CVE-2025-28400 -
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
3.7
CVE-2025-3360 - Glibc: glib prior to 2.82.5 is vulnerable to integer overflow and buffer under-read when parsing aβ¦
A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.
6.2
CVE-2025-3359 - Gnuplot: segmentation fault via io_str_init_static_internal function
A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.