-
CVE-2025-8322 – Ventem e-School Missing Authorization Vulnerability
CVE ID : CVE-2025-8322 Published : July 30, 2025, 4:16 a.m. | 11 hours, 37 minutes ago Description : The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator functions, including creating, modifying, and deleting accounts. They can even escalate any account to system administrator privilege. Severity: 8.8 |…
-
CVE-2025-8292 – Google Chrome Media Stream Use After Free Vulnerability
CVE ID : CVE-2025-8292 Published : July 30, 2025, 2:17 a.m. | 13 hours, 36 minutes ago Description : Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Severity: 8.8 | HIGH Visit the link for…
-
CVE-2025-8320 – Tesla Wall Connector HTTP Content-Length Header Buffer Overflow Remote Code Execution Vulnerability
CVE ID : CVE-2025-8320 Published : July 30, 2025, 1:15 a.m. | 14 hours, 38 minutes ago Description : Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The…
-
CVE-2025-4425 – Lenovo Power Manager Remote Code Execution Vulnerability
CVE ID : CVE-2025-4425 Published : July 30, 2025, 1:15 a.m. | 14 hours, 38 minutes ago Description : The vulnerability was identified in the code developed specifically for Lenovo. Please visit “Lenovo Product Security Advisories and Announcements” webpage for more information about the vulnerability. https://support.lenovo.com/us/en/product_security/home Severity: 8.2 | HIGH Visit the link for more details, such…
-
CVE-2025-4423 – Lenovo Remote Code Execution Vulnerability
CVE ID : CVE-2025-4423 Published : July 30, 2025, 1:15 a.m. | 14 hours, 38 minutes ago Description : The vulnerability was identified in the code developed specifically for Lenovo. Please visit “Lenovo Product Security Advisories and Announcements” webpage for more information about the vulnerability. https://support.lenovo.com/us/en/product_security/home Severity: 8.2 | HIGH Visit the link for more details, such…
-
CVE-2025-4422 – Lenovo SMB Relay Vulnerability
CVE ID : CVE-2025-4422 Published : July 30, 2025, 1:15 a.m. | 14 hours, 38 minutes ago Description : The vulnerability was identified in the code developed specifically for Lenovo. Please visit “Lenovo Product Security Advisories and Announcements” webpage for more information about the vulnerability. https://support.lenovo.com/us/en/product_security/home Severity: 8.2 | HIGH Visit the link for more details, such…
-
CVE-2025-4421 – Lenovo Critical Authentication Bypass Vulnerability
CVE ID : CVE-2025-4421 Published : July 30, 2025, 1:15 a.m. | 14 hours, 38 minutes ago Description : The vulnerability was identified in the code developed specifically for Lenovo. Please visit “Lenovo Product Security Advisories and Announcements” webpage for more information about the vulnerability. https://support.lenovo.com/us/en/product_security/home Severity: 8.2 | HIGH Visit the link for more details, such…
-
CVE-2025-54381 – BentoML SSRF Vulnerability
CVE ID : CVE-2025-54381 Published : July 29, 2025, 11:15 p.m. | 16 hours, 38 minutes ago Description : BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force…
-
CVE-2025-40600 – SonicOS Externally-Controlled Format String Vulnerability
CVE ID : CVE-2025-40600 Published : July 29, 2025, 10:15 p.m. | 17 hours, 38 minutes ago Description : Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline,…
-
CVE-2025-45346 – Bacula-web SQL Injection
CVE ID : CVE-2025-45346 Published : July 29, 2025, 8:15 p.m. | 19 hours, 38 minutes ago Description : SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline,…