8.1

CVSS3.1

CVE-2025-43715 -

Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition.โ€ฆ

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

9.8

CVSS3.1

CVE-2025-28009 -

A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.2

CVSS3.1

CVE-2025-29661 -

Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

9.8

CVSS3.1

CVE-2025-29662 -

A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 4:15 p.m.

7.5

CVSS3.1

CVE-2025-25454 -

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 2:02 p.m.

7.2

CVSS3.1

CVE-2025-29181 -

FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

5.5

CVSS3.1

CVE-2020-36789 - can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context

In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but not always, the case), the 'WARN_ON(in_irq)' in net/core/skbuff.c#skb_rโ€ฆ

๐Ÿ“… Published: April 17, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

8.8

CVSS3.1

CVE-2025-1568 -

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 131.0.6778.268 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipeโ€ฆ

๐Ÿ“… Published: April 16, 2025, 11:06 p.m. ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

8.8

CVSS3.1

CVE-2025-2073 -

Out-of-Bounds Read in ip_set_bitmap_ip.c in Google ChromeOS Kernel Versions 6.1, 5.15, 5.10, 5.4, 4.19. on All devices where Termina is used allows an attacker with CAP_NET_ADMIN privileges to cause memory corruption and potentially escalate privileges via crafted ipset commands.

๐Ÿ“… Published: April 16, 2025, 11:06 p.m. ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.

6.5

CVSS3.1

CVE-2025-1704 -

ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 124.0.6367.34 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.

๐Ÿ“… Published: April 16, 2025, 11:06 p.m. ๐Ÿ”„ Last Modified: April 17, 2025, 8:21 p.m.
Total resulsts: 290935
Page 44 of 29,094
ยซ previous page ยป next page
Filters