7.8

CVSS3.1

CVE-2025-21128 - Substance3D - Stager | Stack-based Buffer Overflow (CWE-121)

Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Jan. 14, 2025, 6:58 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 8:31 p.m.

2.4

CVSS3.1

CVE-2025-23074 - Special:EditProfile exposes the contents of profile fields marked "hidden"/friends or "friends of f…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfile Extension allows Functionality Misuse.This issue affects Mediawiki - SocialProfile Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.

πŸ“… Published: Jan. 14, 2025, 6:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS3.1

CVE-2025-23041 - Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length in Umbraco.Forms

Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade. …

πŸ“… Published: Jan. 14, 2025, 6:54 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 6:54 p.m.

5.3

CVSS3.1

CVE-2024-48854 - Vulnerabilities in TIFF and PCX Image Codecs Impact QNX Software Development Platform

Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.

πŸ“… Published: Jan. 14, 2025, 6:53 p.m. πŸ”„ Last Modified: Jan. 21, 2025, 6:07 p.m.

7.8

CVSS3.1

CVE-2025-21122 - Photoshop Desktop | Integer Underflow (Wrap or Wraparound) (CWE-191)

Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fi…

πŸ“… Published: Jan. 14, 2025, 6:53 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.8

CVSS3.1

CVE-2025-21127 - Photoshop Desktop | Uncontrolled Search Path Element (CWE-427)

Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrar…

πŸ“… Published: Jan. 14, 2025, 6:53 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.7

CVSS3.1

CVE-2025-0474 - Invoice Ninja PDF Rendering Server Side Request Forgery

Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.

πŸ“… Published: Jan. 14, 2025, 6:50 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-23042 - Gradio Blocked Path ACL Bypass Vulnerability

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the letter case of a blocked file or directory path. This…

πŸ“… Published: Jan. 14, 2025, 6:49 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 4:46 p.m.

3.5

CVSS3.1

CVE-2025-23073 - API list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets p…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data. This issue briefly impacted the master branch of MediaWiki’s GlobalBlocking Extension.

πŸ“… Published: Jan. 14, 2025, 6:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.1

CVSS4.0

CVE-2024-50349 - Git does not sanitize URLs when asking for credentials interactively

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using any credential helper), it prints out the host name for whic…

πŸ“… Published: Jan. 14, 2025, 6:43 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 4:42 p.m.
Total resulsts: 349182
Page 7119 of 34,919
Β« previous page Β» next page
Filters