6.9

CVSS4.0

CVE-2025-27111 - Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection

Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed…

πŸ“… Published: March 4, 2025, 3:26 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:18 p.m.

8.6

CVSS4.0

CVE-2025-1424 - Privilege Escalation Through SUID Binary and Developer Mode

A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if they gain physical access to the device. This issue affects InkPad Color 3 in version U743k3.6.8.3671.

πŸ“… Published: March 4, 2025, 3:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS4.0

CVE-2025-1425 - File Read Through Improper Sudo Privilege Management

A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.

πŸ“… Published: March 4, 2025, 3:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-9149 - SQLi in Wind Media's E-Commerce Website Template

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection.This issue affects E-Commerce Website Template: before v1.5.

πŸ“… Published: March 4, 2025, 2:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-27425 - QR code user confirmation bypass with invalid protocol

Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.

πŸ“… Published: March 4, 2025, 1:31 p.m. πŸ”„ Last Modified: April 20, 2026, 8:45 p.m.

4.3

CVSS3.1

CVE-2025-27424 - Firefox Mobile iOS Address Bar Spoof Using Server-Side Redirect to non-http Scheme

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136.

πŸ“… Published: March 4, 2025, 1:31 p.m. πŸ”„ Last Modified: April 20, 2026, 6:30 p.m.

5.4

CVSS3.1

CVE-2025-27426 - Firefox Mobile iOS Full Address Bar Spoof Using Server-Side Redirect to internal error page

Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.

πŸ“… Published: March 4, 2025, 1:31 p.m. πŸ”„ Last Modified: April 20, 2026, 6:30 p.m.

6.5

CVSS3.1

CVE-2025-1938 - Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox…

πŸ“… Published: March 4, 2025, 1:31 p.m. πŸ”„ Last Modified: April 13, 2026, 3:16 p.m.

8.2

CVSS3.1

CVE-2025-1943 - Memory safety bugs fixed in Firefox 136 and Thunderbird 136

Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136 and Thunderbird 136.

πŸ“… Published: March 4, 2025, 1:31 p.m. πŸ”„ Last Modified: April 20, 2026, 6:30 p.m.

7.3

CVSS3.1

CVE-2025-1936 - Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents

jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disg…

πŸ“… Published: March 4, 2025, 1:31 p.m. πŸ”„ Last Modified: April 13, 2026, 3:16 p.m.
Total resulsts: 346576
Page 6198 of 34,658
Β« previous page Β» next page
Filters