3.7

CVSS3.0

CVE-2025-23165 - nodejs: Memory Leak in Node.js ReadFileUtf8 Binding Leading to DoS

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded mem…

πŸ“… Published: May 19, 2025, 1:25 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-4904 - D-Link DI-7003GV2 webgl.data sub_41F0FC information disclosure

A vulnerability has been found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. This vulnerability affects the function sub_41F0FC of the file /H5/webgl.data. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclose…

πŸ“… Published: May 19, 2025, 1 a.m. πŸ”„ Last Modified: May 27, 2025, 4:29 p.m.

6.9

CVSS4.0

CVE-2025-4903 - D-Link DI-7003GV2 webgl.asp sub_41F4F0 unverified password change

A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the function sub_41F4F0 of the file /H5/webgl.asp?tggl_port=0&remote_management=0&http_passwd=game&exec_service=admin-restart. The manipulation leads to unverified password change. It…

πŸ“… Published: May 19, 2025, 12:31 a.m. πŸ”„ Last Modified: May 27, 2025, 4:29 p.m.

6.9

CVSS4.0

CVE-2025-4902 - D-Link DI-7003GV2 versionupdate.data sub_48F4F0 information disclosure

A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this issue is the function sub_48F4F0 of the file /H5/versionupdate.data. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has…

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 1:37 p.m.

7.5

CVSS3.1

CVE-2025-4948 - Libsoup: integer underflow in soup_multipart_new_from_message() leading to denial of service in lib…

A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an inter…

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-4945 - Libsoup: integer overflow in cookie expiration date handling in libsoup

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, a…

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-51106 -

A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle parameter.

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 1 a.m.

7.8

CVSS3.1

CVE-2025-37891 - ALSA: ump: Fix buffer overflow at UMP SysEx message conversion

In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: Fix buffer overflow at UMP SysEx message conversion The conversion function from MIDI 1.0 to UMP packet contains an internal buffer to keep the incoming MIDI bytes, and its size is 4, as it was supposed to be the max s…

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:21 p.m.

8.8

CVSS3.1

CVE-2024-55063 -

Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code via the (1) lang parameter to /international/keyboard/options; the (2) keyboard_layout or (3) keyboard_variant parameter to /international/settings/keyboard; the …

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:25 p.m.

6.5

CVSS3.1

CVE-2025-28371 -

EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:26 p.m.
Total resulsts: 346671
Page 5098 of 34,668
Β« previous page Β» next page
Filters