8.5

CVSS3.1

CVE-2025-49619 -

Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to …

πŸ“… Published: June 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-49128 - Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation

Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a flaw in jackson-core's `JsonLocation._appendSourceDesc` method allows up to 500 bytes of unintended memory conten…

πŸ“… Published: June 6, 2025, 9:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS4.0

CVE-2025-49127 - Kafbat UI vulnerable to Remote Code Execution by JMX in Metrices Configuration

Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute arbitrary code on the server. Version 1.1.0 fixes the issue.

πŸ“… Published: June 6, 2025, 8:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-5799 - Tenda AC8 WifiExtraSet fromSetWirelessRepeat stack-based overflow

A vulnerability was found in Tenda AC8 16.03.34.09. It has been declared as critical. Affected by this vulnerability is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. The attack can be launche…

πŸ“… Published: June 6, 2025, 7:31 p.m. πŸ”„ Last Modified: June 9, 2025, 7:07 p.m.

8.7

CVSS4.0

CVE-2025-5798 - Tenda AC8 SetSysTimeCfg fromSetSysTime stack-based overflow

A vulnerability was found in Tenda AC8 16.03.34.09. It has been classified as critical. Affected is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument timeType leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploi…

πŸ“… Published: June 6, 2025, 7:31 p.m. πŸ”„ Last Modified: June 9, 2025, 7:08 p.m.

5.1

CVSS4.0

CVE-2025-5797 - code-projects Laundry System insert_type.php cross site scripting

A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. This issue affects some unknown processing of the file /data/insert_type.php. The manipulation of the argument Type leads to cross site scripting. The attack may be initiated remotely. The exploit has been …

πŸ“… Published: June 6, 2025, 7 p.m. πŸ”„ Last Modified: June 12, 2025, 4:19 p.m.

5.1

CVSS4.0

CVE-2025-5796 - code-projects Laundry System edit_type.php cross site scripting

A vulnerability has been found in code-projects Laundry System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /data/edit_type.php. The manipulation of the argument Type leads to cross site scripting. The attack can be initiated remotely. The exploit has been …

πŸ“… Published: June 6, 2025, 7 p.m. πŸ”„ Last Modified: June 12, 2025, 4:19 p.m.

8.8

CVSS3.0

CVE-2025-2766 - 70mai A510 Use of Default Password Authentication Bypass Vulnerability

70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of 70mai A510. Authentication is not required to exploit this vulnerability. The specific flaw exists within the default c…

πŸ“… Published: June 6, 2025, 6:53 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 4 p.m.

8.8

CVSS3.1

CVE-2025-3485 - Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability

Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw exists within the implementatio…

πŸ“… Published: June 6, 2025, 6:50 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 4 p.m.

7.8

CVSS3.0

CVE-2025-5481 - Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target mu…

πŸ“… Published: June 6, 2025, 6:49 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 1:31 a.m.
Total resulsts: 348489
Page 5058 of 34,849
Β« previous page Β» next page
Filters