6.9

CVSS4.0

CVE-2025-5050 - FreeFloat FTP Server BELL Command buffer overflow

A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. This issue affects some unknown processing of the component BELL Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and m…

📅 Published: May 21, 2025, 6:31 p.m. 🔄 Last Modified: June 24, 2025, 9:44 a.m.

6.9

CVSS4.0

CVE-2025-5049 - FreeFloat FTP Server APPEND Command buffer overflow

A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. This vulnerability affects unknown code of the component APPEND Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and…

📅 Published: May 21, 2025, 6:31 p.m. 🔄 Last Modified: June 24, 2025, 9:44 a.m.

7

CVSS4.0

CVE-2025-2261 - TIBCO BPM Enterprise XSS Vulnerability

Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application.

📅 Published: May 21, 2025, 6:29 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-3751 - TIBCO ActiveMatrix BusinessWorks SQL Injection Vulnerability

The component listed above contains a vulnerability that can be exploited by an attacker to perform a SQL Injection attack. This could lead to unauthorised access to the database and exposure of sensitive information

📅 Published: May 21, 2025, 6:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2025-48069 - ejson2env has insufficient input sanitization

ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `ejson2env` tool has a vulnerability related to how it writes to `stdout`. Specifically, the tool is intended to write an export statement for environment variables and their values…

📅 Published: May 21, 2025, 5:43 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2025-48064 - GitHub Desktop vulnerable to maliciously crafted file renames leading to information disclosure

GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to access a network share…

📅 Published: May 21, 2025, 5:40 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-48063 - XWiki Platform Security Authorization Bridge allows users with just edit right can enforce required…

XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part of the security model of required rights is that a user who doesn't have a right also cannot define that right as required right. That way, users who are edit…

📅 Published: May 21, 2025, 5:38 p.m. 🔄 Last Modified: June 24, 2025, 9:44 a.m.

7.7

CVSS4.0

CVE-2025-48060 - AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt)

jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz);`. As of time of publication, no patched versions…

📅 Published: May 21, 2025, 5:32 p.m. 🔄 Last Modified: Nov. 3, 2025, 7:16 p.m.

5.3

CVSS4.0

CVE-2025-5033 - XiaoBingby TeaCMS addUser cross-site request forgery

A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/me/teacms/controller/admin/UserManageController/addUser. The manipulation leads to cross-site request forgery. The attack can be launc…

📅 Published: May 21, 2025, 5:31 p.m. 🔄 Last Modified: June 20, 2025, 4:15 p.m.

4.6

CVSS4.0

CVE-2025-47291 - containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespac…

containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes limits are not honor…

📅 Published: May 21, 2025, 5:26 p.m. 🔄 Last Modified: Sept. 19, 2025, 5:25 p.m.
Total resulsts: 345147
Page 4893 of 34,515
« previous page » next page
Filters