5.5

CVSS3.1

CVE-2025-46398 - Xfig: fig2dev stack-overflow via read_objects

In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.

πŸ“… Published: April 23, 2025, 8:55 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

7.8

CVSS3.1

CVE-2025-46397 - Xfig: xfig: stack-overflow allows possible code execution via local input manipulation

A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.

πŸ“… Published: April 23, 2025, 8:55 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 4:15 a.m.

7.5

CVSS3.1

CVE-2025-32818 -

A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.

πŸ“… Published: April 23, 2025, 7:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-3907 - Search API Solr - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-046

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue affects Search API Solr: from 0.0.0 before 4.3.9.

πŸ“… Published: April 23, 2025, 5:08 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:37 p.m.

7.3

CVSS3.1

CVE-2025-3904 - Sportsleague - Critical - Unsupported - SA-CONTRIB-2025-045

Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.

πŸ“… Published: April 23, 2025, 5:08 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:37 p.m.

7.3

CVSS3.1

CVE-2025-3903 - UEditor - 百度编辑器 - Critical - Unsupported - SA-CONTRIB-2025-044

Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.

πŸ“… Published: April 23, 2025, 5:08 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:37 p.m.

6.1

CVSS3.1

CVE-2025-3902 - Block Class - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-043

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class allows Cross-Site Scripting (XSS).This issue affects Block Class: from 4.0.0 before 4.0.1.

πŸ“… Published: April 23, 2025, 5:08 p.m. πŸ”„ Last Modified: June 17, 2025, 12:54 a.m.

6.1

CVSS3.1

CVE-2025-3901 - Bootstrap Site Alert - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-042

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4.

πŸ“… Published: April 23, 2025, 5:07 p.m. πŸ”„ Last Modified: June 18, 2025, 9:01 p.m.

6.1

CVSS3.1

CVE-2025-3900 - Colorbox - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-041

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: from 0.0.0 before 2.1.3.

πŸ“… Published: April 23, 2025, 5:07 p.m. πŸ”„ Last Modified: June 20, 2025, 4:22 p.m.

7.2

CVSS3.0

CVE-2025-2773 - BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability

BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers. Although authentication is required to exploit this vulnerability, t…

πŸ“… Published: April 23, 2025, 4:52 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:38 a.m.
Total resulsts: 346529
Page 5420 of 34,653
Β« previous page Β» next page
Filters