9.8

CVSS3.1

CVE-2024-50645 -

MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 25, 2025, 10:08 p.m.

6.1

CVSS3.1

CVE-2025-50858 -

Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 2:15 p.m.

6.1

CVSS3.1

CVE-2025-50733 -

NextChat contains a cross-site scripting (XSS) vulnerability in the HTMLPreview component of artifacts.tsx that allows attackers to execute arbitrary JavaScript code when HTML content is rendered in the AI chat interface. The vulnerability occurs because user-influenced HTML from AI responses is re…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 2:15 p.m.

5.5

CVSS3.1

CVE-2025-38657 - wifi: rtw89: mcc: prevent shift wrapping in rtw89_core_mlsr_switch()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: mcc: prevent shift wrapping in rtw89_core_mlsr_switch() The "link_id" value comes from the user via debugfs. If it's larger than BITS_PER_LONG then that would result in shift wrapping and potentially an out of bound…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

9.8

CVSS3.1

CVE-2025-55398 -

An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed Encoding Rules), asn1c-generated decoders fail to enforce INTEGER constraints when the bound is positive and exceeds 32 bits in length, potentially allowing incorrect or malicious i…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 2:15 p.m.

5.5

CVSS3.1

CVE-2025-38661 - platform/x86: alienware-wmi-wmax: Fix `dmi_system_id` array

In the Linux kernel, the following vulnerability has been resolved: platform/x86: alienware-wmi-wmax: Fix `dmi_system_id` array Add missing empty member to `awcc_dmi_table`.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

7.5

CVSS3.1

CVE-2024-53494 -

Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 2:15 p.m.

8.8

CVSS3.1

CVE-2025-52085 -

An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint. Successful exploitation enables extraction of sensitive database information, including but not limited to, the database server banner and…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 2:15 p.m.

7.0

CVSS3.1

CVE-2025-38660 - [ceph] parse_longname(): strrchr() expects NUL-terminated string

In the Linux kernel, the following vulnerability has been resolved: [ceph] parse_longname(): strrchr() expects NUL-terminated string ... and parse_longname() is not guaranteed that. That's the reason why it uses kmemdup_nul() to build the argument for kstrtou64(); the problem is, kstrtou64() is …

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

9.8

CVSS3.1

CVE-2025-55611 -

D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 2:15 p.m.
Total resulsts: 307401
Page 83 of 30,741
Β« previous page Β» next page
Filters