7.2

CVSS3.1

CVE-2025-29180 -

In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

9.8

CVSS3.1

CVE-2025-29042 -

An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 18, 2025, 3:12 p.m.

6.5

CVSS3.1

CVE-2025-28101 -

An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

3.3

CVSS3.1

CVE-2025-26269 -

DragonflyDB Dragonfly through 1.28.2 allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

3.3

CVSS3.1

CVE-2025-26268 -

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

8.4

CVSS3.1

CVE-2024-55211 -

An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.8

CVSS3.1

CVE-2021-47670 - can: peak_usb: fix use after free bugs

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the peak_usb_netif_rx_ni(). Reordering the line…

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.2

CVSS3.1

CVE-2025-29039 -

An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.1

CVSS3.1

CVE-2024-55238 -

OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

0.0

CVE-2025-29316 -

An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive information

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.
Total resulsts: 290985
Page 47 of 29,099
Β« previous page Β» next page
Filters