5.5

CVSS3.1

CVE-2025-29478 -

An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: Dec. 8, 2025, 6:49 p.m.

9.8

CVSS3.1

CVE-2025-28410 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:53 p.m.

6.2

CVSS3.1

CVE-2025-29481 - libbpf: Heap Buffer Overflow in libbpf

Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under…

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: Feb. 25, 2026, 7:51 a.m.

9.8

CVSS3.1

CVE-2025-28406 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 4:32 p.m.

8.8

CVSS3.1

CVE-2025-28409 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:59 p.m.

9.8

CVSS3.1

CVE-2025-28408 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 7 p.m.

5.4

CVSS3.1

CVE-2024-46494 -

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 12:33 p.m.

4.0

CVSS3.1

CVE-2025-29479 - hiredis: Heap Buffer Overflow in Hiredis

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 12, 2025, 5:15 p.m.

9.8

CVSS3.1

CVE-2025-28412 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:41 p.m.

9.8

CVSS3.1

CVE-2025-28402 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 5:17 p.m.
Total resulsts: 349182
Page 5996 of 34,919
Β« previous page Β» next page
Filters