6.2

CVSS3.1

CVE-2025-3359 - Gnuplot: segmentation fault via io_str_init_static_internal function

A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: May 3, 2026, 9:12 a.m.

6.7

CVSS3.1

CVE-2025-28401 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 5:19 p.m.

7.2

CVSS3.1

CVE-2025-28403 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 4:48 p.m.

6.2

CVSS3.1

CVE-2025-29482 -

Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 4:10 p.m.

9.8

CVSS3.1

CVE-2025-28413 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 2:58 p.m.

8.1

CVSS3.1

CVE-2025-32409 -

Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurr…

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-28407 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 7 p.m.

9.8

CVSS3.1

CVE-2025-28411 -

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:45 p.m.

6.1

CVSS3.1

CVE-2025-29594 -

A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scripti…

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-29480 - gdal: Buffer Overflow in GDAL

Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invalid and could not be reproduced.

πŸ“… Published: April 7, 2025, midnight πŸ”„ Last Modified: July 24, 2025, 2:34 p.m.
Total resulsts: 349182
Page 5997 of 34,919
Β« previous page Β» next page
Filters