4.9

CVSS3.1

CVE-2025-46655 -

CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted Java…

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.5

CVSS3.1

CVE-2025-46646 - Ghostscript: Mishandling of Overlong UTF-8 Encoding in Artifex Ghostscript's decode_utf8 Function

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:31 p.m.

6.4

CVSS3.1

CVE-2024-53636 -

An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Jan. 29, 2026, 5:57 p.m.

8.1

CVSS3.1

CVE-2025-5987 - Libssh: invalid return code for chacha20 poly1305 with openssl backend

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the …

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: March 20, 2026, 9:17 p.m.

2.9

CVSS3.1

CVE-2025-46656 -

python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:24 p.m.

4.9

CVSS3.1

CVE-2025-46654 -

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 3:14 p.m.

3.1

CVSS3.1

CVE-2025-46653 - formidable: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Formidable

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string ne…

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:30 p.m.

6.1

CVSS3.1

CVE-2025-46652 -

In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is not propagated to the extracted files. NOTE: this is disputed because Mark-of-the-Web propagation can increase risk via secur…

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-46333 - z2d OOB composition could lead to invalid memory access and corruption

z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from one surface to another using `z2d.compositor.StrideCompositor.run`, and higher-level operations when the anti-aliasing mode is set to `.default` (such as `Context.fill`, `Context.…

πŸ“… Published: April 25, 2025, 8:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-3935 - ScreenConnect Exposure to ASP.NET ViewState Code Injection

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys.Β  It is important to note that to obtain these machine keys, privi…

πŸ“… Published: April 25, 2025, 6:27 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.
Total resulsts: 349182
Page 5659 of 34,919
Β« previous page Β» next page
Filters