7.5

CVSS3.1

CVE-2025-1713 - deadlock potential with VT-d and legacy PCI device pass-through

When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, itself involving acquiring of a lock, is done in a context where acquiring that lock is unsafe. This can lead to a deadlock.

πŸ“… Published: July 17, 2025, 1:59 p.m. πŸ”„ Last Modified: July 17, 2025, 3:15 p.m.

4.6

CVSS3.1

CVE-2025-53928 - MaxKB has RCE in MCP call

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the issue.

πŸ“… Published: July 17, 2025, 1:56 p.m. πŸ”„ Last Modified: July 17, 2025, 7:57 p.m.

4.6

CVSS3.1

CVE-2025-53927 - MaxKB sandbox bypass

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed because MaxKB only restricts the execution permissions of files in a specific directory. Therefore, an attacker can use the `shutil.copy2` method in Python to copy the command they …

πŸ“… Published: July 17, 2025, 1:50 p.m. πŸ”„ Last Modified: July 17, 2025, 7:56 p.m.

9.1

CVSS3.1

CVE-2025-53909 - mailcow: dockerized vulnerable to SSTI in Quota and Quarantine Notification Template

mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantine alerts. The template rendering engine allows te…

πŸ“… Published: July 17, 2025, 1:47 p.m. πŸ”„ Last Modified: July 17, 2025, 7:54 p.m.

6.5

CVSS3.1

CVE-2025-40924 - Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely

Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated from a (usually SHA-1) hash of a simple counter, the epoch time, the built-in rand function, the PID and the current Catalyst context. This information is of low entropy. The PID wi…

πŸ“… Published: July 17, 2025, 1:33 p.m. πŸ”„ Last Modified: July 17, 2025, 8:15 p.m.

5.1

CVSS4.0

CVE-2025-5346 - File removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner applica…

Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is p…

πŸ“… Published: July 17, 2025, 12:45 p.m. πŸ”„ Last Modified: July 17, 2025, 1:44 p.m.

8.5

CVSS4.0

CVE-2025-5344 - Exposed AIDL service allowing for tampering of system secure settings in Bluebird kiosk application

Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image. This issue affects al…

πŸ“… Published: July 17, 2025, 12:45 p.m. πŸ”„ Last Modified: July 17, 2025, 1:48 p.m.

6.3

CVSS4.0

CVE-2025-5345 - Exposed AIDL service allowing to read and delete files with system-level privileges in Bluebird fil…

Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's storage with system-level…

πŸ“… Published: July 17, 2025, 12:45 p.m. πŸ”„ Last Modified: July 17, 2025, 1:51 p.m.

5.3

CVSS3.1

CVE-2025-4302 - Stop User Enumeration < 1.7.3 - Protection Bypass

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

πŸ“… Published: July 17, 2025, 7:37 a.m. πŸ”„ Last Modified: July 17, 2025, 2:15 p.m.

8.7

CVSS4.0

CVE-2025-7735 - UNIMAX|Hospital Information System - SQL Injection

The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

πŸ“… Published: July 17, 2025, 3:20 a.m. πŸ”„ Last Modified: July 17, 2025, 1:37 p.m.
Total resulsts: 302283
Page 6 of 30,229
Β« previous page Β» next page
Filters