7.8

CVSS3.0

CVE-2025-2015 - Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability

Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a…

πŸ“… Published: March 11, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 5:25 p.m.

7.8

CVSS3.0

CVE-2025-2014 - Ashlar-Vellum Cobalt VS File Parsing Use of Uninitialized Variable Remote Code Execution Vulnerabil…

Ashlar-Vellum Cobalt VS File Parsing Use of Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the targ…

πŸ“… Published: March 11, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 4:27 p.m.

7.8

CVSS3.0

CVE-2025-2013 - Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability

Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a…

πŸ“… Published: March 11, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 8:37 p.m.

7.8

CVSS3.0

CVE-2025-2012 - Ashlar-Vellum Cobalt VS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

Ashlar-Vellum Cobalt VS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must vis…

πŸ“… Published: March 11, 2025, 8:42 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 4:27 p.m.

4.8

CVSS4.0

CVE-2025-2208 - aitangbao springboot-manager Filename upload cross site scripting

A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue affects some unknown processing of the file /sysFiles/upload of the component Filename Handler. The manipulation of the argument name leads to cross site scripting. The attack may be…

πŸ“… Published: March 11, 2025, 8:31 p.m. πŸ”„ Last Modified: May 21, 2025, 5:55 p.m.

5.5

CVSS3.1

CVE-2025-21170 - Substance3D - Modeler | NULL Pointer Dereference (CWE-476)

Substance3D - Modeler versions 1.15.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this iss…

πŸ“… Published: March 11, 2025, 8:11 p.m. πŸ”„ Last Modified: April 14, 2025, 3:10 p.m.

7.8

CVSS3.1

CVE-2025-27181 - Substance3D - Modeler | Use After Free (CWE-416)

Substance3D - Modeler versions 1.15.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: March 11, 2025, 8:11 p.m. πŸ”„ Last Modified: April 18, 2025, 2:50 p.m.

5.5

CVSS3.1

CVE-2025-27180 - Substance3D - Modeler | Out-of-bounds Read (CWE-125)

Substance3D - Modeler versions 1.15.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a v…

πŸ“… Published: March 11, 2025, 8:11 p.m. πŸ”„ Last Modified: April 18, 2025, 2:50 p.m.

7.8

CVSS3.1

CVE-2025-27173 - Substance3D - Modeler | Heap-based Buffer Overflow (CWE-122)

Substance3D - Modeler versions 1.15.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: March 11, 2025, 8:11 p.m. πŸ”„ Last Modified: April 18, 2025, 3:51 p.m.

4.8

CVSS4.0

CVE-2025-2207 - aitangbao springboot-manager dept cross site scripting

A vulnerability classified as problematic was found in aitangbao springboot-manager 3.0. This vulnerability affects unknown code of the file /sys/dept. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the pu…

πŸ“… Published: March 11, 2025, 8 p.m. πŸ”„ Last Modified: May 21, 2025, 5:49 p.m.
Total resulsts: 349182
Page 6374 of 34,919
Β« previous page Β» next page
Filters