5.3

CVSS3.1

CVE-2025-51082 -

Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack-based buffer overflow.

πŸ“… Published: July 24, 2025, midnight πŸ”„ Last Modified: July 28, 2025, 5 p.m.

8.6

CVSS3.1

CVE-2025-51087 -

Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.

πŸ“… Published: July 24, 2025, midnight πŸ”„ Last Modified: July 28, 2025, 5:02 p.m.

7.8

CVSS4.0

CVE-2025-54365 - fastapi-guard patch contains bypassable RegEx

fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In version 3.0.1, the regular expression patched to mitigate the ReDoS vulnerability by limiting the length of string fails to catch inputs that exceed this l…

πŸ“… Published: July 23, 2025, 10:11 p.m. πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

9.3

CVSS4.0

CVE-2016-15044 - Kaltura < 11.1.0-2 PHP Object Injection RCE

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sending a specially crafted serialized PHP object in the kdata GET…

πŸ“… Published: July 23, 2025, 10:02 p.m. πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

4.1

CVSS3.1

CVE-2025-32019 - Harbor's repository description page allows for XSS

Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be exploited to inject XSS code. This is fixed in…

πŸ“… Published: July 23, 2025, 8:38 p.m. πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

7.8

CVSS3.1

CVE-2025-54377 - Roo Code Lacks Line Break Validation in its Command Execution Tool

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks (\n) in its command input, allowing potential bypass of the allow-list mechanism. The project appears to lack parsing or validation logic to prevent m…

πŸ“… Published: July 23, 2025, 8:36 p.m. πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

7.5

CVSS3.1

CVE-2025-53537 - LibHTP's memory leak with lzma can lead to resource starvation

LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, there is a traffic-induced memory leak that can starve the process of memory, leading to loss of visibility. To workaround this issue, set `suricata.yaml app-layer.protocols.http.l…

πŸ“… Published: July 23, 2025, 8:35 p.m. πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

7.7

CVSS3.1

CVE-2025-47281 - Kyverno's Improper JMESPath Variable Evaluation Leads to Denial of Service

Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial of Service (DoS) vulnerability exists due to improper handling of JMESPath variable substitutions. Attackers with permissions to create or update Kyverno policies can craft expres…

πŸ“… Published: July 23, 2025, 8:35 p.m. πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

7.1

CVSS4.0

CVE-2025-53942 - authentik has an insufficient check for account active status during OAuth/SAML authentication

authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3, deactivated users who registered through OAuth/SAML or linked their accounts to O…

πŸ“… Published: July 23, 2025, 8:35 p.m. πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.

5.9

CVSS4.0

CVE-2025-8058 - glibc: Double free in glibc

The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation…

πŸ“… Published: July 23, 2025, 7:57 p.m. πŸ”„ Last Modified: July 25, 2025, 3:29 p.m.
Total resulsts: 303658
Page 69 of 30,366
Β« previous page Β» next page
Filters