7.7

CVSS4.0

CVE-2025-48060 - AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)

jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz);`. As of time of publication, no patched versionsโ€ฆ

๐Ÿ“… Published: May 21, 2025, 5:32 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 7:16 p.m.

5.3

CVSS4.0

CVE-2025-5033 - XiaoBingby TeaCMS addUser cross-site request forgery

A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/me/teacms/controller/admin/UserManageController/addUser. The manipulation leads to cross-site request forgery. The attack can be launcโ€ฆ

๐Ÿ“… Published: May 21, 2025, 5:31 p.m. ๐Ÿ”„ Last Modified: June 20, 2025, 4:15 p.m.

4.6

CVSS4.0

CVE-2025-47291 - containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespacโ€ฆ

containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes limits are not honorโ€ฆ

๐Ÿ“… Published: May 21, 2025, 5:26 p.m. ๐Ÿ”„ Last Modified: Sept. 19, 2025, 5:25 p.m.

7.7

CVSS4.0

CVE-2025-46822 - Unauthenticated Arbitrary File Read via Absolute Path

OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized accesโ€ฆ

๐Ÿ“… Published: May 21, 2025, 5:23 p.m. ๐Ÿ”„ Last Modified: May 21, 2025, 8:24 p.m.

5.7

CVSS4.0

CVE-2025-2102 -

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.

๐Ÿ“… Published: May 21, 2025, 5:19 p.m. ๐Ÿ”„ Last Modified: May 21, 2025, 8:24 p.m.

4.3

CVSS3.1

CVE-2025-5020 -

Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client This vulnerability affects Firefox for iOS < 139.

๐Ÿ“… Published: May 21, 2025, 5:18 p.m. ๐Ÿ”„ Last Modified: June 13, 2025, 6:55 p.m.

5.9

CVSS4.0

CVE-2025-0372 -

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.

๐Ÿ“… Published: May 21, 2025, 5:12 p.m. ๐Ÿ”„ Last Modified: May 21, 2025, 8:24 p.m.

6.9

CVSS4.0

CVE-2025-5032 - Campcodes Online Shopping Portal edit-category.php sql injection

A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit has been dโ€ฆ

๐Ÿ“… Published: May 21, 2025, 5 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 2:12 p.m.

2.3

CVSS4.0

CVE-2025-5031 - Ackites KillWxapkg wxapkg File Decompression resource consumption

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the component wxapkg File Decompression Handler. The manipulation leads to resource consumption. The attack may be initiated remotely. The complexity of an atโ€ฆ

๐Ÿ“… Published: May 21, 2025, 5 p.m. ๐Ÿ”„ Last Modified: June 23, 2025, 8:17 a.m.

6.1

CVSS3.1

CVE-2025-20250 -

A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A succโ€ฆ

๐Ÿ“… Published: May 21, 2025, 4:48 p.m. ๐Ÿ”„ Last Modified: July 14, 2025, 8:34 p.m.
Total resulsts: 343919
Page 4771 of 34,392
ยซ previous page ยป next page
Filters