10

CVSS4.0

CVE-2024-48841 - Remote Code Execution (RCE) Vulnerabilities

Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older.

πŸ“… Published: Jan. 27, 2025, 7:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-0734 - y_project RuoYi Whitelist getBeanName deserialization

A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the component Whitelist. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and…

πŸ“… Published: Jan. 27, 2025, 7 p.m. πŸ”„ Last Modified: May 13, 2025, 8:47 p.m.

2

CVSS4.0

CVE-2025-0733 - Postman profapi.dll untrusted search path

A vulnerability, which was classified as problematic, was found in Postman up to 11.20 on Windows. This affects an unknown part in the library profapi.dll. The manipulation leads to untrusted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploi…

πŸ“… Published: Jan. 27, 2025, 6 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2025-0732 - Discord profapi.dll untrusted search path

A vulnerability, which was classified as problematic, has been found in Discord up to 1.0.9177 on Windows. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to untrusted search path. The attack needs to be approached locally. The complexity of a…

πŸ“… Published: Jan. 27, 2025, 6 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-24365 - vaultwarden allows escalation of privilege via variable confusion in OrgHeaders trait

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the organization as an unprivileged user) and be…

πŸ“… Published: Jan. 27, 2025, 5:49 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 1:56 p.m.

7.2

CVSS3.1

CVE-2025-24364 - vaultwarden allows RCE in the admin panel

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The attacker could then change some settings to use sendmail as mail agent but adjust…

πŸ“… Published: Jan. 27, 2025, 5:46 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 2:16 p.m.

7.5

CVSS3.1

CVE-2025-24357 - vLLM allows a malicious model RCE by torch.load in hf_model_weights_iterator

vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses the torch.load function and the weights_only parameter defaults to False. When torch.load loads malic…

πŸ“… Published: Jan. 27, 2025, 5:38 p.m. πŸ”„ Last Modified: June 27, 2025, 7:30 p.m.

6.9

CVSS4.0

CVE-2025-24356 - UDP traffic amplification via fastd's fast reconnect feature

fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP. When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peers has moved to a new address and initiate a reconnect by sending a handshake packet. This "fast reco…

πŸ“… Published: Jan. 27, 2025, 5:31 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 2:15 a.m.

5.3

CVSS3.1

CVE-2025-24354 - imgproxy is vulnerable to SSRF against 0.0.0.0

imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.

πŸ“… Published: Jan. 27, 2025, 5:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-23197 - matrix-hookshot has a Potential Denial of Service when Hookshot is configured with GitHub support

matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. When Hookshot 6 version 6.0.1 or below, or Hookshot 5 version 5.4.1 or below, is configured with GitHub support, it is vulnerable to a Denial of Service (DoS) whereby it can crash on restart due…

πŸ“… Published: Jan. 27, 2025, 5:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6942 of 34,919
Β« previous page Β» next page
Filters