5.5
CVE-2025-46398 - Xfig: fig2dev stack-overflow via read_objects
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.
7.8
CVE-2025-46397 - Xfig: xfig: stack-overflow allows possible code execution via local input manipulation
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.
7.5
CVE-2025-32818 -
A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.
4.3
CVE-2025-3907 - Search API Solr - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-046
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue affects Search API Solr: from 0.0.0 before 4.3.9.
7.3
CVE-2025-3904 - Sportsleague - Critical - Unsupported - SA-CONTRIB-2025-045
Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.
7.3
CVE-2025-3903 - UEditor - ηΎεΊ¦ηΌθΎε¨ - Critical - Unsupported - SA-CONTRIB-2025-044
Vulnerability in Drupal UEditor - ηΎεΊ¦ηΌθΎε¨.This issue affects UEditor - ηΎεΊ¦ηΌθΎε¨: *.*.
6.1
CVE-2025-3902 - Block Class - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-043
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class allows Cross-Site Scripting (XSS).This issue affects Block Class: from 4.0.0 before 4.0.1.
6.1
CVE-2025-3901 - Bootstrap Site Alert - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-042
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4.
6.1
CVE-2025-3900 - Colorbox - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-041
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: from 0.0.0 before 2.1.3.
7.2
CVE-2025-2773 - BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability
BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers. Although authentication is required to exploit this vulnerability, tβ¦