7.7

CVSS4.0

CVE-2025-49001 - Dataease Authentication Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds are available.

📅 Published: June 3, 2025, 8:33 p.m. 🔄 Last Modified: June 5, 2025, 2:07 p.m.

6.8

CVSS4.0

CVE-2025-48999 - Dataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE Vulnerability

DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, it will not enter the if statement and will …

📅 Published: June 3, 2025, 8:31 p.m. 🔄 Last Modified: June 5, 2025, 2:07 p.m.

8.7

CVSS4.0

CVE-2025-5527 - Tenda RX3 SetStaticRouteCfg save_staticroute_data stack-based overflow

A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotel…

📅 Published: June 3, 2025, 8:31 p.m. 🔄 Last Modified: June 9, 2025, 3:11 p.m.

6.3

CVSS4.0

CVE-2025-5525 - Jrohy trojan linux.go LogChan os command injection

A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/util/linux.go. The manipulation of the argument c leads to os command injection. The attack can be initiated remotely. The complexity of an at…

📅 Published: June 3, 2025, 8 p.m. 🔄 Last Modified: June 6, 2025, 5:27 p.m.

5.1

CVSS4.0

CVE-2025-5523 - enilu web-flash File Upload upload fileService.upload cross site scripting

A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripti…

📅 Published: June 3, 2025, 7:31 p.m. 🔄 Last Modified: June 9, 2025, 3:12 p.m.

6.9

CVSS4.0

CVE-2025-35036 - hibernate-validator insecure default Expression Language interpolation

Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of…

📅 Published: June 3, 2025, 7:27 p.m. 🔄 Last Modified: Sept. 18, 2025, 2:19 p.m.

6.9

CVSS4.0

CVE-2025-5522 - jack0240 魏 bskms 蓝天幼儿园管理系统 User Creation addUser improper authorization

A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the component User Creation Handler. The manipulation leads to improper authorizatio…

📅 Published: June 3, 2025, 7 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-5521 - WuKongOpenSource WukongCRM updataPassword cross-site request forgery

A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/user/updataPassword. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploi…

📅 Published: June 3, 2025, 6:31 p.m. 🔄 Last Modified: June 9, 2025, 3:12 p.m.

7.3

CVSS4.0

CVE-2025-48998 - Dataease MYSQL JDBC File Reading Vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.10. No…

📅 Published: June 3, 2025, 6:27 p.m. 🔄 Last Modified: June 9, 2025, 3:13 p.m.

8.7

CVSS4.0

CVE-2025-48997 - Multer vulnerable to Denial of Service via unhandled exception

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an upload file request with an empty string field name. This request cause…

📅 Published: June 3, 2025, 6:21 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346571
Page 4924 of 34,658
« previous page » next page
Filters