0.0

CVE-2025-54988 - Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to…

πŸ“… Published: Aug. 20, 2025, 8:08 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 8:08 p.m.

8.7

CVSS4.0

CVE-2025-9246 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 check_port_conflict stack-based overflow

A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Impacted is the function check_port_conflict of the file /goform/check_port_conflict. Executing manipulation of the argument single_port_rule/port_range_rule c…

πŸ“… Published: Aug. 20, 2025, 8:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 8:02 p.m.

8.7

CVSS4.0

CVE-2025-9245 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 WPSSTAPINEnr stack-based overflow

A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function WPSSTAPINEnr of the file /goform/WPSSTAPINEnr. Performing manipulation of the argument ssid results in stack-based buffe…

πŸ“… Published: Aug. 20, 2025, 8:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 8:02 p.m.

5.3

CVSS4.0

CVE-2025-9244 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 addStaticRoute os command injection

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaticRoute of the file /goform/addStaticRoute. Such manipulation of the argument staticRoute_I…

πŸ“… Published: Aug. 20, 2025, 7:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:32 p.m.

5.3

CVSS4.0

CVE-2025-9241 - elunez eladmin exportUser csv injection

A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

πŸ“… Published: Aug. 20, 2025, 7:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:32 p.m.

4.8

CVSS4.0

CVE-2025-43757 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.…

πŸ“… Published: Aug. 20, 2025, 7:13 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:13 p.m.

7.5

CVSS3.1

CVE-2025-5115 - MadeYouReset HTTP/2 vulnerability

In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume…

πŸ“… Published: Aug. 20, 2025, 7:07 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:07 p.m.

5.1

CVSS4.0

CVE-2025-43746 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.…

πŸ“… Published: Aug. 20, 2025, 6:37 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 6:37 p.m.

5.3

CVSS4.0

CVE-2025-9240 - elunez eladmin info information disclosure

A security flaw has been discovered in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file /auth/info. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

πŸ“… Published: Aug. 20, 2025, 6:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 6:32 p.m.

6.3

CVSS4.0

CVE-2025-9239 - elunez eladmin DES Key EncryptUtils.java EncryptUtils inadequate encryption

A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function EncryptUtils of the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java of the component DES Key Handler. The manipulation of the argument STR_PARAM with the input Passw0rd l…

πŸ“… Published: Aug. 20, 2025, 6:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 6:15 p.m.
Total resulsts: 306461
Page 7 of 30,647
Β« previous page Β» next page
Filters