8.8

CVSS3.1

CVE-2025-22923 -

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: July 17, 2025, 6:24 p.m.

5.5

CVSS3.1

CVE-2025-21990 - drm/amdgpu: NULL-check BO's backing store when determining GFX12 PTE flags

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: NULL-check BO's backing store when determining GFX12 PTE flags PRT BOs may not have any backing store, so bo->tbo.resource will be NULL. Check for that before dereferencing. (cherry picked from commit 3e3fcd29b505cebโ€ฆ

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 6:15 p.m.

5.5

CVSS3.1

CVE-2025-21987 - drm/amdgpu: init return value in amdgpu_ttm_clear_buffer

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: init return value in amdgpu_ttm_clear_buffer Otherwise an uninitialized value can be returned if amdgpu_res_cleared returns true for all regions. Possibly closes: https://gitlab.freedesktop.org/drm/amd/-/issues/3812 โ€ฆ

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 30, 2025, 7:20 p.m.

5.5

CVSS3.1

CVE-2025-21988 - fs/netfs/read_collect: add to next->prev_donated

In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated If multiple subrequests donate data to the same "next" request (depending on the subrequest completion order), each of them would overwrite the `prev_donated` field, causing data cโ€ฆ

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2025, 6:56 p.m.

6.1

CVSS3.1

CVE-2025-29719 -

SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 2:27 p.m.

9.8

CVSS3.1

CVE-2025-29085 -

SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-21991 - x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes

In the Linux kernel, the following vulnerability has been resolved: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes Currently, load_microcode_amd() iterates over all NUMA nodes, retrieves their CPU masks and unconditionally accesses per-CPU data for the first CPU of each โ€ฆ

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.8

CVSS3.1

CVE-2025-27556 - django: Django DoS Unicode Attack

An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack viโ€ฆ

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 3, 2025, 3:34 p.m.

7.2

CVSS3.1

CVE-2025-30090 -

mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers, because JavaScript payloads are mishandled after $encoded has been set to true.

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-22925 -

OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.

๐Ÿ“… Published: April 2, 2025, midnight ๐Ÿ”„ Last Modified: April 29, 2025, 1:44 p.m.
Total resulsts: 349182
Page 6055 of 34,919
ยซ previous page ยป next page
Filters