4.8

CVSS4.0

CVE-2025-3163 - InternLM LMDeploy conf.py open code injection

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has be…

πŸ“… Published: April 3, 2025, 3:31 p.m. πŸ”„ Last Modified: April 23, 2025, 3:31 p.m.

9

CVSS3.1

CVE-2025-22457 -

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

πŸ“… Published: April 3, 2025, 3:20 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.8

CVSS3.1

CVE-2025-29987 -

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privile…

πŸ“… Published: April 3, 2025, 3:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.8

CVSS3.1

CVE-2024-4877 -

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

πŸ“… Published: April 3, 2025, 3:11 p.m. πŸ”„ Last Modified: April 29, 2025, 7:45 p.m.

4.8

CVSS4.0

CVE-2025-3162 - InternLM LMDeploy PT File utils.py load_weight_ckpt deserialization

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. …

πŸ“… Published: April 3, 2025, 3 p.m. πŸ”„ Last Modified: April 23, 2025, 10:29 p.m.

5.4

CVSS3.1

CVE-2025-0272 - HCL DevOps Deploy / HCL Launch is susceptible to an HTML injection vulnerability

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

πŸ“… Published: April 3, 2025, 2:56 p.m. πŸ”„ Last Modified: April 10, 2025, 1:27 p.m.

8.7

CVSS4.0

CVE-2025-3161 - Tenda AC10 ShutdownSetAdd stack-based overflow

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function ShutdownSetAdd of the file /goform/ShutdownSetAdd. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been d…

πŸ“… Published: April 3, 2025, 2:31 p.m. πŸ”„ Last Modified: April 9, 2025, 4:27 p.m.

4.8

CVSS4.0

CVE-2025-3160 - Open Asset Import Library Assimp File SceneCombiner.cpp AddNodeHashes out-of-bounds

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read.…

πŸ“… Published: April 3, 2025, 2:31 p.m. πŸ”„ Last Modified: May 28, 2025, 2:11 p.m.

4.8

CVSS4.0

CVE-2025-3159 - Open Asset Import Library Assimp ASE File ASEParser.cpp ParseLV4MeshBonesVertices heap-based overfl…

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer…

πŸ“… Published: April 3, 2025, 2 p.m. πŸ”„ Last Modified: July 17, 2025, 9:44 p.m.

4.8

CVSS4.0

CVE-2025-3158 - Open Asset Import Library Assimp LWO File LWOAnimation.cpp UpdateAnimRangeSetup heap-based overflow

A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation lead…

πŸ“… Published: April 3, 2025, 1:31 p.m. πŸ”„ Last Modified: July 17, 2025, 9:45 p.m.
Total resulsts: 343919
Page 5506 of 34,392
Β« previous page Β» next page
Filters