4.8

CVSS4.0

CVE-2025-4748 - Absolute path traversal in zip:unzip/1,2

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files lib/stdlib/src/zip.erl and program routines zip:unzip/1, zip:unzip/2, zi…

📅 Published: June 16, 2025, 11 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-47869 - Apache NuttX RTOS: examples/xmlrpc: Fix calls buffers size.

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc application. In this example application device stats structure that stored remotely provided parameters had hardcoded buffer size which could lead to buffe…

📅 Published: June 16, 2025, 11 a.m. 🔄 Last Modified: June 17, 2025, 7:37 p.m.

4.8

CVSS4.0

CVE-2025-6119 - Open Asset Import Library Assimp BVHLoader.cpp ReadNodeChannels use after free

A vulnerability classified as critical has been found in Open Asset Import Library Assimp up to 5.4.3. Affected is the function Assimp::BVHLoader::ReadNodeChannels in the library assimp/code/AssetLib/BVH/BVHLoader.cpp. The manipulation of the argument pNode leads to use after free. Attacking locall…

📅 Published: June 16, 2025, 11 a.m. 🔄 Last Modified: June 17, 2025, 7:38 p.m.

9.8

CVSS3.1

CVE-2025-47868 - Apache NuttX RTOS: tools/bdf-converter.: tools/bdf-converter: Fix loop termination condition.

Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither part of NuttX RTOS nor Applications runtime, but active bdf-…

📅 Published: June 16, 2025, 11 a.m. 🔄 Last Modified: June 17, 2025, 7:38 p.m.

6.9

CVSS4.0

CVE-2025-6118 - Das Parking Management System 停车场管理系统 API search sql injection

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been rated as critical. This issue affects some unknown processing of the file /vehicle/search of the component API. The manipulation of the argument vehicleTypeCode leads to sql injection. The attack may be initiated …

📅 Published: June 16, 2025, 10:31 a.m. 🔄 Last Modified: Oct. 9, 2025, 5:08 p.m.

6.9

CVSS4.0

CVE-2025-6117 - Das Parking Management System 停车场管理系统 API Search sql injection

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been declared as critical. This vulnerability affects unknown code of the file /Reservations/Search of the component API. The manipulation of the argument Value leads to sql injection. The attack can be initiated remot…

📅 Published: June 16, 2025, 10 a.m. 🔄 Last Modified: Oct. 9, 2025, 5:12 p.m.

4.9

CVSS3.1

CVE-2025-25265 - Unauthenticated File Read via Web Interface

A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to read files from the system’s file structure.

📅 Published: June 16, 2025, 9:46 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-25264 - Overly Permissive CORS Policy in WAGO Device Manager

An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.

📅 Published: June 16, 2025, 9:45 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-6116 - Das Parking Management System 停车场管理系统 API Search sql injection

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been classified as critical. This affects an unknown part of the file /IntraFieldVehicle/Search of the component API. The manipulation of the argument Value leads to sql injection. It is possible to initiate the attack…

📅 Published: June 16, 2025, 9:31 a.m. 🔄 Last Modified: Oct. 9, 2025, 5:14 p.m.

8.4

CVSS4.0

CVE-2025-3464 -

A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

📅 Published: June 16, 2025, 9:06 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5023 of 34,919
« previous page » next page
Filters