2.3

CVSS4.0

CVE-2025-27104 - double eval in For List Iter in Vyper

vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a for loop. While the iterator expression cannot produce multiple writes, it can consume side effects produced in the loop body (e.g. read a storage variable upd…

πŸ“… Published: Feb. 21, 2025, 9:32 p.m. πŸ”„ Last Modified: March 28, 2025, 8:05 p.m.

2.3

CVSS4.0

CVE-2025-27105 - AugAssign evaluation order causing OOB write within the object in Vyper

vyper is a Pythonic Smart Contract Language for the EVM. Vyper handles AugAssign statements by first caching the target location to avoid double evaluation. However, in the case when target is an access to a DynArray and the rhs modifies the array, the cached target will evaluate first, and the bou…

πŸ“… Published: Feb. 21, 2025, 9:27 p.m. πŸ”„ Last Modified: March 28, 2025, 8:02 p.m.

7.7

CVSS4.0

CVE-2025-27106 - Code injection in binance-trading-bot

binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a command injection vulnerability in the `/restore` endpoint. The restore endpoint of binance-trading-bot i…

πŸ“… Published: Feb. 21, 2025, 9:18 p.m. πŸ”„ Last Modified: Feb. 22, 2025, 4:15 p.m.

6.8

CVSS3.1

CVE-2019-8900 -

A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows arbitrary code to be executed on the device. Exploiting the vulnerability requires physical access to the devi…

πŸ“… Published: Feb. 21, 2025, 9:17 p.m. πŸ”„ Last Modified: July 29, 2025, 6:01 p.m.

7.3

CVSS3.1

CVE-2025-27109 - Lack of Escaping of HTML in JSX Fragments allows for Cross-site Scripting in solid-js

solid-js is a declarative, efficient, and flexible JavaScript library for building user interfaces. In affected versions Inserts/JSX expressions inside illegal inlined JSX fragments lacked escaping, allowing user input to be rendered as HTML when put directly inside JSX fragments. This issue has be…

πŸ“… Published: Feb. 21, 2025, 9:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-27108 - Cross-site Scripting vulnerability due to improper use of string.replace in dom-expressions

dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering. In affected versions the use of javascript's `.replace()` opens up to potential Cross-site Scripting (XSS) vulnerabilities with the special replacement patterns beginning with `$`. Particularly, when the attributes of `Meta` ta…

πŸ“… Published: Feb. 21, 2025, 9:09 p.m. πŸ”„ Last Modified: Feb. 27, 2025, 8:18 p.m.

8.1

CVSS3.0

CVE-2025-25282 - Potential Insecure Direct Object Reference (IDOR) vulnerability in ragflow

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability that may lead to unauthorized cross-tenant access (list tenant user accounts, add user account into…

πŸ“… Published: Feb. 21, 2025, 9:04 p.m. πŸ”„ Last Modified: July 16, 2025, 2:24 p.m.

6.9

CVSS4.0

CVE-2025-1555 - hzmanyun Education and Training System saveImage unrestricted upload

A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public…

πŸ“… Published: Feb. 21, 2025, 9 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 2:12 a.m.

5.1

CVSS4.0

CVE-2025-1548 - iteachyou Dreamer CMS edit cross site scripting

A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/archives/edit. The manipulation of the argument editorValue/answer/content leads to cross site scripting. The attack can be initiated remotely. T…

πŸ“… Published: Feb. 21, 2025, 5 p.m. πŸ”„ Last Modified: April 4, 2025, 4:40 p.m.

8.6

CVSS3.1

CVE-2025-1403 - Qiskit SDK denial of service

Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.

πŸ“… Published: Feb. 21, 2025, 4:55 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 3:25 p.m.
Total resulsts: 349182
Page 6662 of 34,919
Β« previous page Β» next page
Filters