0.0

CVE-2025-55367 -

Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 1:42 p.m.

0.0

CVE-2025-55370 -

Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 2 p.m.

0.0

CVE-2024-50641 -

An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token.

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 6:01 p.m.

0.0

CVE-2025-52352 -

Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-up option on the login page UI. However, the sign-up API endpoint remains publicly accessible and functional, allowing unauthenticated users to regis…

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 5:52 p.m.

0.0

CVE-2024-45438 -

An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email …

πŸ“… Published: Aug. 21, 2025, midnight πŸ”„ Last Modified: Aug. 21, 2025, 4:20 p.m.

8.8

CVSS3.1

CVE-2025-9141 - vllm: quen3: RCE in vllm tool call parser for qwen3coder

A vulnerability was found in vLLM's Qwen3 Coder tool parser. Since this parser uses Python's eval() function, it poses a risk of arbitrary code execution. This vulnerability appears during the parameter conversion process when the parser attempts to handle complex data types.

πŸ“… Published: Aug. 20, 2025, 11:37 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:37 p.m.

5.3

CVSS4.0

CVE-2025-9264 - Xuxueli xxl-job Jobs JobInfoController.java remove resource injection

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource id…

πŸ“… Published: Aug. 20, 2025, 11:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:32 p.m.

5.3

CVSS4.0

CVE-2025-9263 - Xuxueli xxl-job JobLogController.java getJobsByGroup resource injection

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to improper control of resource identifiers. T…

πŸ“… Published: Aug. 20, 2025, 11:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:02 p.m.

6.3

CVSS4.0

CVE-2025-9262 - wong2 mcp-cli oAuth provider.js redirectToAuthorization os command injection

A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component oAuth Handler. This manipulation causes os command injection. The attack may be initiated remotely. The attack is considered to have high complexity. T…

πŸ“… Published: Aug. 20, 2025, 11:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:02 p.m.

8.7

CVSS4.0

CVE-2025-9253 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_doSpecifySiteSurvey stack-based overflow

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function RP_doSpecifySiteSurvey of the file /goform/RP_doSpecifySiteSurvey. The manipulation of the argument…

πŸ“… Published: Aug. 20, 2025, 10:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 10:32 p.m.
Total resulsts: 306500
Page 9 of 30,650
Β« previous page Β» next page
Filters