4.8

CVSS4.0

CVE-2025-4059 - code-projects Prison Management System Prison_Mgmt_Sys addrecord stack-based overflow

A vulnerability classified as critical was found in code-projects Prison Management System 1.0. This vulnerability affects the function addrecord of the component Prison_Mgmt_Sys. The manipulation of the argument filename leads to stack-based buffer overflow. An attack has to be approached locally.โ€ฆ

๐Ÿ“… Published: April 29, 2025, noon ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

5.3

CVSS3.1

CVE-2025-3891 - Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

๐Ÿ“… Published: April 29, 2025, 11:56 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

0.0

CVE-2024-58099 - vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame Andrew and Nikolay reported connectivity issues with Cilium's service load-balancing in case of vmxnet3. If a BPF program for native XDP adds an encapsulation header such โ€ฆ

๐Ÿ“… Published: April 29, 2025, 11:45 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

5.3

CVSS4.0

CVE-2025-3929 - Stored XSS vulnerability in MDaemon Email Server

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and accesโ€ฆ

๐Ÿ“… Published: April 29, 2025, 11:36 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

6.9

CVSS4.0

CVE-2025-4058 - Projectworlds Online Examination System Bloodgroop_process.php sql injection

A vulnerability classified as critical has been found in Projectworlds Online Examination System 1.0. This affects an unknown part of the file /Bloodgroop_process.php. The manipulation of the argument Pat_BloodGroup1 leads to sql injection. It is possible to initiate the attack remotely. The exploiโ€ฆ

๐Ÿ“… Published: April 29, 2025, 11:31 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 2:15 p.m.

4.3

CVSS3.0

CVE-2025-1194 - Regular Expression Denial of Service (ReDoS) in huggingface/transformers

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability occurs in the SubWordJapaneseTokenizer class, where regular expressionsโ€ฆ

๐Ÿ“… Published: April 29, 2025, 11:30 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2025-30194 - Denial of service via crafted DoH exchange

When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.9 version. A wโ€ฆ

๐Ÿ“… Published: April 29, 2025, 11:25 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 2:15 p.m.

4.3

CVSS3.1

CVE-2025-3452 - SecuPress Free <= 2.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Insโ€ฆ

The SecuPress Free โ€” WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'secupress_reinstall_plugins_admin_ajax_cb' function in all versions up to, and including, 2.3.9. This makes it possible for authenticated attackeโ€ฆ

๐Ÿ“… Published: April 29, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

6.4

CVSS3.1

CVE-2025-2893 - Gutenverse <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block

The Gutenverse โ€“ Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributโ€ฆ

๐Ÿ“… Published: April 29, 2025, 6:37 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

3.5

CVSS3.1

CVE-2024-12273 - Calculated Fields Form < 5.2.62 - Admin+ Stored XSS

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: April 29, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 9:05 p.m.
Total resulsts: 291760
Page 7 of 29,176
ยซ previous page ยป next page
Filters