5.9

CVSS3.1

CVE-2025-24963 - Browser mode serves arbitrary files in vitest

Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by `browser.api.host: true`, an attacker can send a request to that handler from remote to ge…

πŸ“… Published: Feb. 4, 2025, 7:36 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 2:44 p.m.

9.7

CVSS3.1

CVE-2025-24964 - Remote Code Execution when accessing a malicious website while Vitest API server is listening

Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks. When `api` option is enabled (Vitest UI enables it), Vitest star…

πŸ“… Published: Feb. 4, 2025, 7:36 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 2:50 p.m.

9.3

CVSS4.0

CVE-2025-0960 - AutomationDirect C-more EA9 HMI Classic Buffer Overflow

AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving remote code execution on the affected device.

πŸ“… Published: Feb. 4, 2025, 7:34 p.m. πŸ”„ Last Modified: Feb. 4, 2025, 8:15 p.m.

8.8

CVSS3.1

CVE-2025-24968 - Business Logic And Unrestricted Project Deletion Lead To Take Over the System in reNgine

reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tester` or `auditor` to delete all projects in the system. This can lead to a complete system takeover by redirecting the …

πŸ“… Published: Feb. 4, 2025, 7:28 p.m. πŸ”„ Last Modified: May 13, 2025, 6:39 p.m.

7.4

CVSS4.0

CVE-2025-24967 - Stored XSS on Admin Panel When Deleting a User in reNgine

reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. An attacker can exploit this issue by injecting malicious payloads into the username field during user creation. This v…

πŸ“… Published: Feb. 4, 2025, 7:28 p.m. πŸ”„ Last Modified: May 13, 2025, 6:43 p.m.

5.3

CVSS4.0

CVE-2025-24966 - HTML Injection in reNgine

reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes user inputs, allowing attackers to inject arbitrary HTML code. In this scenario, the vulnerability exists in the "Add Target" functionality of the appli…

πŸ“… Published: Feb. 4, 2025, 7:26 p.m. πŸ”„ Last Modified: May 13, 2025, 6:46 p.m.

9.5

CVSS4.0

CVE-2025-24971 - OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop

DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in the DumbDrop application, `/upload/init` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely wh…

πŸ“… Published: Feb. 4, 2025, 6:53 p.m. πŸ”„ Last Modified: Feb. 4, 2025, 8:15 p.m.

6.3

CVSS3.1

CVE-2025-0451 -

Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)

πŸ“… Published: Feb. 4, 2025, 6:53 p.m. πŸ”„ Last Modified: April 8, 2025, 12:25 p.m.

5.4

CVSS3.1

CVE-2025-0445 -

Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Feb. 4, 2025, 6:53 p.m. πŸ”„ Last Modified: April 8, 2025, 12:25 p.m.

6.3

CVSS3.1

CVE-2025-0444 -

Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Feb. 4, 2025, 6:53 p.m. πŸ”„ Last Modified: April 8, 2025, 12:26 p.m.
Total resulsts: 344062
Page 6338 of 34,407
Β« previous page Β» next page
Filters