6.9

CVSS4.0

CVE-2025-4553 - PHPGurukul Apartment Visitors Management System bwdates-reports-details.php sql injection

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may bโ€ฆ

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: May 16, 2025, 5:08 p.m.

6.1

CVSS3.1

CVE-2025-22247 - Insecure file handling vulnerability

VMware Tools contains an insecure file handling vulnerability.ย A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure file operations within that VM.

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-44175 -

Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 1:39 p.m.

6.5

CVSS3.1

CVE-2024-55466 -

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 1:38 a.m.

5.7

CVSS4.0

CVE-2025-46805 - Screen has a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when โ€ฆ

Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root.

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2025-46804 - Screen 5.0.0 and older versions allow file existence tests when installed setuid-root

A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-56523 -

Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method.

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: July 1, 2025, 8:03 p.m.

7.5

CVSS3.1

CVE-2025-45835 -

A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the environment variable value CONTENT_LENGTH, causing the program to crash and โ€ฆ

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 1:57 a.m.

9.8

CVSS3.1

CVE-2025-44830 -

EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 1:49 p.m.

6.5

CVSS3.1

CVE-2025-44176 -

Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.

๐Ÿ“… Published: May 12, 2025, midnight ๐Ÿ”„ Last Modified: May 23, 2025, 7 p.m.
Total resulsts: 347806
Page 5326 of 34,781
ยซ previous page ยป next page
Filters