9.8

CVSS3.1

CVE-2025-25221 -

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.

πŸ“… Published: Feb. 18, 2025, 12:10 a.m. πŸ”„ Last Modified: Sept. 15, 2025, 5:48 p.m.

4.3

CVSS3.1

CVE-2025-25471 -

FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2024-57259 -

sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not considered in a size calculation.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

8.1

CVSS3.1

CVE-2024-56883 -

Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for other employees, even though they do not have the opt…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Sept. 25, 2025, 1:27 p.m.

2

CVSS3.1

CVE-2024-57257 -

A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

8

CVSS3.1

CVE-2025-25894 -

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 3:46 p.m.

6.4

CVSS3.1

CVE-2022-41545 -

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transpor…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: June 6, 2025, 6:01 p.m.

9.9

CVSS3.1

CVE-2024-39327 -

Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-21702 - pfifo_tail_enqueue: Drop new packet when sch->limit == 0

In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will drop a packet in scheduler's queue and decrease scheduler's qlen by one. Then, pfifo_tail_…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 9:16 a.m.

5.9

CVSS3.1

CVE-2025-26466 - Openssh: denial-of-service in openssh

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Feb. 10, 2026, 6:16 p.m.
Total resulsts: 348602
Page 6649 of 34,861
Β« previous page Β» next page
Filters