8.7

CVSS4.0

CVE-2025-6143 - TOTOLINK EX1200T HTTP POST Request formNtp buffer overflow

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formNtp of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to laโ€ฆ

๐Ÿ“… Published: June 16, 2025, 10:31 p.m. ๐Ÿ”„ Last Modified: June 23, 2025, 7:29 p.m.

5.2

CVSS4.0

CVE-2025-48992 - Group-Office vulnerable to blind XSS

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a stored and blind cross-site scripting (XSS) vulnerability exists in the Name Field of the user profile. A malicious attacker can change their name to a javascript payload, whiโ€ฆ

๐Ÿ“… Published: June 16, 2025, 10:17 p.m. ๐Ÿ”„ Last Modified: Sept. 4, 2025, 3:57 p.m.

5.3

CVSS4.0

CVE-2025-6142 - Intera InHire server-side request forgery

A vulnerability was found in Intera InHire up to 20250530. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument 29chcotoo9 leads to server-side request forgery. The attack can be launched remotely. The exploit has been discloโ€ฆ

๐Ÿ“… Published: June 16, 2025, 10 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-6141 - GNU ncurses parse_entry.c postprocess_termcap stack-based overflow

A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading toโ€ฆ

๐Ÿ“… Published: June 16, 2025, 10 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2025-43200 - Logic Issue in iCloud Photo/Video Processing Leading to Potential Exploitation

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed wheโ€ฆ

๐Ÿ“… Published: June 16, 2025, 9:36 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 1:30 a.m.

4.8

CVSS4.0

CVE-2025-6140 - spdlog pattern_formatter-inl.h scoped_padder resource consumption

A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This affects the function scoped_padder in the library include/spdlog/pattern_formatter-inl.h. The manipulation leads to resource consumption. It is possible to launch the attack on the local host. The exploit hโ€ฆ

๐Ÿ“… Published: June 16, 2025, 9:31 p.m. ๐Ÿ”„ Last Modified: July 2, 2025, 6:58 p.m.

2.1

CVSS4.0

CVE-2025-49134 - Weblate exposes personal IP address via e-mail

Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.

๐Ÿ“… Published: June 16, 2025, 9:03 p.m. ๐Ÿ”„ Last Modified: July 16, 2025, 2:35 p.m.

2

CVSS4.0

CVE-2025-6139 - TOTOLINK T10 shadow.sample hard-coded password

A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can only be initiated within the local network. Thโ€ฆ

๐Ÿ“… Published: June 16, 2025, 9 p.m. ๐Ÿ”„ Last Modified: June 26, 2025, 4:27 p.m.

4.9

CVSS3.1

CVE-2025-47951 - Weblate lacks rate limiting when verifying second factor

Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in versโ€ฆ

๐Ÿ“… Published: June 16, 2025, 8:57 p.m. ๐Ÿ”„ Last Modified: July 16, 2025, 2:32 p.m.

7.2

CVSS4.0

CVE-2025-32800 - Conda-build vulnerable to supply chain attack vector due to pyproject.toml referring to dependencieโ€ฆ

Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the package, and then exploitโ€ฆ

๐Ÿ“… Published: June 16, 2025, 8:38 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 10:10 p.m.
Total resulsts: 349182
Page 5017 of 34,919
ยซ previous page ยป next page
Filters