7.8

CVSS3.1

CVE-2025-0285 - CVE-2025-0285

Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.

πŸ“… Published: March 3, 2025, 4:25 p.m. πŸ”„ Last Modified: Sept. 9, 2025, 1:57 p.m.

8.4

CVSS3.1

CVE-2025-0286 - CVE-2025-0286

Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.

πŸ“… Published: March 3, 2025, 4:25 p.m. πŸ”„ Last Modified: Sept. 9, 2025, 1:59 p.m.

5.1

CVSS3.1

CVE-2025-0287 - CVE-2025-0287

Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.

πŸ“… Published: March 3, 2025, 4:25 p.m. πŸ”„ Last Modified: Sept. 5, 2025, 12:08 p.m.

7.8

CVSS3.1

CVE-2025-0288 - CVE-2025-0288

Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.

πŸ“… Published: March 3, 2025, 4:24 p.m. πŸ”„ Last Modified: Sept. 9, 2025, 2 p.m.

7.8

CVSS3.1

CVE-2025-0289 - CVE-2025-0289

Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.

πŸ“… Published: March 3, 2025, 4:24 p.m. πŸ”„ Last Modified: Sept. 9, 2025, 2:03 p.m.

7.5

CVSS3.1

CVE-2025-27421 - Goroutine Leak in Abacus SSE Implementation

Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in the Abacus server's Server-Sent Events (SSE) implementation. The issue occurs when clients disconnect from the /stream endpoint, as the server fails to properly clean up resources …

πŸ“… Published: March 3, 2025, 4:19 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-27419 - Denial of Service (DoS) in WeGIA due to Recursive Crawling of Dynamic URLs

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Denial of Service (DoS) vulnerability exists in WeGIA. This vulnerability allows any unauthenticated user to cause the server to become unresponsive by performing aggressive spidering. The vulnerabilit…

πŸ“… Published: March 3, 2025, 4:07 p.m. πŸ”„ Last Modified: March 4, 2025, 4:09 p.m.

6.4

CVSS4.0

CVE-2025-27420 - WeGIA contains a Stored Cross-Site Scripting (XSS) in 'atendido_parentesco_adicionar.php' via the '…

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the atendido_parentesco_adicionar.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious script…

πŸ“… Published: March 3, 2025, 4:05 p.m. πŸ”„ Last Modified: April 10, 2025, 6:29 p.m.

9.8

CVSS3.1

CVE-2024-55532 - Apache Ranger: Improper Neutralization of Formula Elements in a CSV File

Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.

πŸ“… Published: March 3, 2025, 4:04 p.m. πŸ”„ Last Modified: May 21, 2025, 4:12 p.m.

6.4

CVSS4.0

CVE-2025-27418 - WeGIA contains a Stored Cross-Site Scripting (XSS) in 'adicionar_tipo_atendido.php' via the 'tipo' …

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the adicionar_tipo_atendido.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into…

πŸ“… Published: March 3, 2025, 4:03 p.m. πŸ”„ Last Modified: April 10, 2025, 6:37 p.m.
Total resulsts: 349182
Page 6474 of 34,919
Β« previous page Β» next page
Filters