9.8

CVSS3.1

CVE-2025-6179 - ChromeOS Extension Disablement and Developer Mode Bypass via ExtHang3r and ExtPrint3r Exploits

Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and ExtPrint3r tools.

πŸ“… Published: June 16, 2025, 4:56 p.m. πŸ”„ Last Modified: July 2, 2025, 6:23 p.m.

7.4

CVSS3.1

CVE-2025-6177 - ChromeOS MiniOS Root Code Execution Bypass While Dev Mode Blocked

Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during developer mode entry and MiniOS access, even w…

πŸ“… Published: June 16, 2025, 4:43 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.7

CVSS4.0

CVE-2025-6130 - TOTOLINK EX1200T HTTP POST Request formStats buffer overflow

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack may be initiated r…

πŸ“… Published: June 16, 2025, 4:31 p.m. πŸ”„ Last Modified: June 20, 2025, 2:39 p.m.

5.1

CVSS4.0

CVE-2025-2327 - FlashArray KEK Logging Vulnerability

A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.

πŸ“… Published: June 16, 2025, 4:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2025-48945 - pycares has a Use-After-Free Vulnerability

pycares is a Python module which provides an interface to c-ares. c-ares is a C library that performs DNS requests and name resolutions asynchronously. Prior to version 4.9.0, pycares is vulnerable to a use-after-free condition that occurs when a Channel object is garbage collected while DNS querie…

πŸ“… Published: June 16, 2025, 4:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-5309 - Remote Support & Privileged Remote Access server side template injection

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.

πŸ“… Published: June 16, 2025, 4:06 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

8.7

CVSS4.0

CVE-2025-6129 - TOTOLINK EX1200T HTTP POST Request formSaveConfig buffer overflow

A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be…

πŸ“… Published: June 16, 2025, 4 p.m. πŸ”„ Last Modified: July 2, 2025, 5:40 p.m.

8.7

CVSS4.0

CVE-2025-6128 - TOTOLINK EX1200T HTTP POST Request formWirelessTbl buffer overflow

A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknown part of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to init…

πŸ“… Published: June 16, 2025, 3:31 p.m. πŸ”„ Last Modified: June 27, 2025, 2:46 p.m.

7.5

CVSS3.1

CVE-2025-48976 - Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fi…

πŸ“… Published: June 16, 2025, 3 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

5.1

CVSS4.0

CVE-2025-6127 - PHPGurukul Nipah Virus Testing Management System search-report.php cross site scripting

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search-report.php. The manipulation of the argument serachdata leads to cross site scripting. The attack may be laun…

πŸ“… Published: June 16, 2025, 3 p.m. πŸ”„ Last Modified: June 24, 2025, 3:52 p.m.
Total resulsts: 346617
Page 4763 of 34,662
Β« previous page Β» next page
Filters