7.8

CVSS3.1

CVE-2025-4802 - glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions …

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

5.9

CVSS3.1

CVE-2025-32407 -

Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user. This is a critical misconfiguration in the way the browser validates the identit…

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:30 p.m.

6.5

CVSS3.1

CVE-2024-40120 -

seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 2:09 p.m.

8.2

CVSS3.1

CVE-2025-47809 -

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center …

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

10

CVSS3.1

CVE-2025-47916 -

Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenti…

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: June 20, 2025, 5:42 p.m.

7.8

CVSS3.1

CVE-2025-37890 - net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc As described in Gerrard's report [1], we have a UAF case when an hfsc class has a netem child qdisc. The crux of the issue is that hfsc is assuming that …

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 5:11 p.m.

4.5

CVSS3.1

CVE-2025-48174 -

In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:19 p.m.

2.9

CVSS3.1

CVE-2025-48188 -

libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.

πŸ“… Published: May 16, 2025, midnight πŸ”„ Last Modified: July 17, 2025, 8:33 p.m.

5.3

CVSS4.0

CVE-2025-4729 - TOTOLINK A3002R/A3002RU HTTP POST Request formMapDelDevice command injection

A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads …

πŸ“… Published: May 15, 2025, 11:31 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

5.3

CVSS4.0

CVE-2025-47930 - Zulip Server has access control bypass for restrictions on creation of specific channel types

Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A similar technique work…

πŸ“… Published: May 15, 2025, 11:17 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 2:26 a.m.
Total resulsts: 343943
Page 4853 of 34,395
Β« previous page Β» next page
Filters