7.8

CVSS3.1

CVE-2025-0835 - GPU DDK - _WrapExtMemReleasePages called twice if _FlushUMVirtualRange fails

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.

πŸ“… Published: March 24, 2025, 11:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-0478 - GPU DDK - PMMETA_PROTECT PMR can be exported as dma-buf file / GEM object

Software installed and run as a non-privileged user may conduct improper GPU system calls to issue reads and writes to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel…

πŸ“… Published: March 24, 2025, 11:37 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-2702 - Softwin WMX3 ImageAdd.ashx ImageAdd unrestricted upload

A vulnerability, which was classified as critical, has been found in Softwin WMX3 3.1. This issue affects the function ImageAdd of the file /ImageAdd.ashx. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the…

πŸ“… Published: March 24, 2025, 9:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-2701 - AMTT Hotel Broadband Operation System port_setup.php popen os command injection

A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0. This vulnerability affects the function popen of the file /manager/network/port_setup.php. The manipulation of the argument SwitchVersion/SwitchWrite/SwitchIP/SwitchIndex/SwitchState leads to os command i…

πŸ“… Published: March 24, 2025, 9 a.m. πŸ”„ Last Modified: Oct. 17, 2025, 5:11 p.m.

5.1

CVSS4.0

CVE-2025-2700 - michelson Dante Editor Insert Link cross site scripting

A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the pu…

πŸ“… Published: March 24, 2025, 8:31 a.m. πŸ”„ Last Modified: April 1, 2025, 8:47 p.m.

5.1

CVSS4.0

CVE-2025-2699 - GetmeUK ContentTools Image cross site scripting

A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation of the argument onload leads to cross site scripting. The attack may be launched remotely. The expl…

πŸ“… Published: March 24, 2025, 8 a.m. πŸ”„ Last Modified: July 22, 2025, 3:07 p.m.

5.3

CVSS4.0

CVE-2025-2690 - yiisoft Yii2 MockClass.php generate deserialization

A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been d…

πŸ“… Published: March 24, 2025, 7:31 a.m. πŸ”„ Last Modified: March 24, 2025, 5:15 p.m.

5.3

CVSS4.0

CVE-2025-2689 - yiisoft Yii2 SortableIterator.php getIterator deserialization

A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit ha…

πŸ“… Published: March 24, 2025, 7 a.m. πŸ”„ Last Modified: March 24, 2025, 5:17 p.m.

5.3

CVSS4.0

CVE-2025-2688 - TOTOLINK A3000RU Syslog Configuration File ExportSyslog.sh access control

A vulnerability classified as problematic was found in TOTOLINK A3000RU up to 5.9c.5185. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ExportSyslog.sh of the component Syslog Configuration File Handler. The manipulation leads to improper access controls. The attack…

πŸ“… Published: March 24, 2025, 6:31 a.m. πŸ”„ Last Modified: July 2, 2025, 6:03 p.m.

5.3

CVSS4.0

CVE-2025-2687 - PHPGurukul eLearning System Image index.php unrestricted upload

A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been dis…

πŸ“… Published: March 24, 2025, 6 a.m. πŸ”„ Last Modified: March 27, 2025, 6:14 p.m.
Total resulsts: 349182
Page 6243 of 34,919
Β« previous page Β» next page
Filters