4.8

CVSS4.0

CVE-2025-3136 - PyTorch CUDACachingAllocator.cpp torch.cuda.memory.caching_allocator_delete memory corruption

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The e…

πŸ“… Published: April 3, 2025, 3:31 a.m. πŸ”„ Last Modified: May 28, 2025, 3:59 p.m.

5.3

CVSS4.0

CVE-2025-3135 - fcba_zzm ics-park Smart Park Management System update sql injection

A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerability affects unknown code of the file /api/system/dept/update. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the p…

πŸ“… Published: April 3, 2025, 1:31 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 2:43 p.m.

5.3

CVSS4.0

CVE-2025-3134 - code-projects Payroll Management System add_overtime.php sql injection

A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation of the argument rate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclo…

πŸ“… Published: April 3, 2025, 1:31 a.m. πŸ”„ Last Modified: May 14, 2025, 4:26 p.m.

5.1

CVSS4.0

CVE-2025-3153 - Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 - CSRF and XSS in Concrete CMS Cust…

Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are not properly sanitized in the output when a country is not specified.Β  Attackers are limited to individuals whom a site administrator has grante…

πŸ“… Published: April 3, 2025, 12:17 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 3:54 p.m.

7.5

CVSS3.1

CVE-2025-32049 - Libsoup: denial of service attack to websocket server

A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS).

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:15 a.m.

9.1

CVSS3.1

CVE-2025-22927 -

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: July 17, 2025, 6:18 p.m.

7.8

CVSS3.1

CVE-2025-21999 - proc: fix UAF in proc_get_inode()

In the Linux kernel, the following vulnerability has been resolved: proc: fix UAF in proc_get_inode() Fix race between rmmod and /proc/XXX's inode instantiation. The bug is that pde->proc_ops don't belong to /proc, it belongs to a module, therefore dereferencing it after /proc entry has been reg…

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

6.5

CVSS3.1

CVE-2025-32053 - Libsoup: heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space()

A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read.

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 11:08 p.m.

6.5

CVSS3.1

CVE-2025-32052 - Libsoup: heap buffer overflow in sniff_unknown()

A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read.

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 11:08 p.m.

9.8

CVSS3.1

CVE-2025-22928 -

OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.

πŸ“… Published: April 3, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 7:52 p.m.
Total resulsts: 343749
Page 5498 of 34,375
Β« previous page Β» next page
Filters