7.8

CVSS3.1

CVE-2022-47090 -

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check needed for num_exp_tile_columns

๐Ÿ“… Published: Jan. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-57184 -

An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file.

๐Ÿ“… Published: Jan. 24, 2025, midnight ๐Ÿ”„ Last Modified: June 27, 2025, 7:34 p.m.

9.8

CVSS3.1

CVE-2024-50695 -

SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT messages, due to missing MQTT topic bounds checks.

๐Ÿ“… Published: Jan. 24, 2025, midnight ๐Ÿ”„ Last Modified: May 29, 2025, 4:02 p.m.

8.1

CVSS3.1

CVE-2024-50697 -

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.

๐Ÿ“… Published: Jan. 24, 2025, midnight ๐Ÿ”„ Last Modified: May 29, 2025, 4:02 p.m.

9.8

CVSS3.1

CVE-2024-50694 -

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not check the bounds of the buffer that is used to store the message. This may lead to a stack-based buffer overflow.

๐Ÿ“… Published: Jan. 24, 2025, midnight ๐Ÿ”„ Last Modified: May 29, 2025, 4:02 p.m.

6.8

CVSS3.1

CVE-2024-57095 -

SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.

๐Ÿ“… Published: Jan. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 2:23 a.m.

4.9

CVSS3.1

CVE-2021-42718 - Sensitive data unnecessarily returned from authenticated API

Information Disclosure in API in Replicated Replicated Classic versions prior to 2.53.1 on all platforms allows authenticated users with Admin Console access to retrieve sensitive data, including application secrets, via accessing container definitions with environment variables through the Admin Cโ€ฆ

๐Ÿ“… Published: Jan. 23, 2025, 10:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-0577 - Glibc: vdso getrandom acceleration may return predictable randomness

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.

๐Ÿ“… Published: Jan. 23, 2025, 10:40 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-0693 - Issue with AWS Sign-in IAM User Login Flow - Possible Username Enumeration

Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS account.

๐Ÿ“… Published: Jan. 23, 2025, 9:22 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-23012 - Fedora Repository fedoraIntCallUser default credentials

Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of โ€ฆ

๐Ÿ“… Published: Jan. 23, 2025, 8:25 p.m. ๐Ÿ”„ Last Modified: Oct. 7, 2025, 4:47 p.m.
Total resulsts: 349182
Page 6983 of 34,919
ยซ previous page ยป next page
Filters