CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-54216

    Last Modified: 26 Feb 2026

    InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54217

    Last Modified: 26 Feb 2026

    InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54215

    Last Modified: 26 Feb 2026

    InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54218

    Last Modified: 26 Feb 2026

    InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54223

    Last Modified: 26 Feb 2026

    InCopy versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54219

    Last Modified: 26 Feb 2026

    InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54221

    Last Modified: 26 Feb 2026

    InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54220

    Last Modified: 26 Feb 2026

    InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54211

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54207

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54214

    Last Modified: 13 Aug 2025

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54224

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54213

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54210

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54225

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54209

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54208

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54227

    Last Modified: 13 Aug 2025

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54228

    Last Modified: 13 Aug 2025

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54226

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54212

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54206

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    8.2
    High

    CVE-2025-55165

    Last Modified: 15 Apr 2026

    Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre database. Prior to version 0.8.3, the debug pack generated by Autocaliweb can expose sensitive configuration data, including API keys. This occurs because the to_dict() method, used to serialize configuration for the debug pack, doesn't adequately filter out sensitive fields such as API tokens. Users, unaware of the full contents, might share these debug packs, inadvertently leaking their private API keys. This issue has been patched in version 0.8.3.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54205

    Last Modified: 14 Aug 2025

    Substance3D - Sampler versions 5.0.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54188

    Last Modified: 13 Aug 2025

    Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54193

    Last Modified: 13 Aug 2025

    Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54194

    Last Modified: 13 Aug 2025

    Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-54187

    Last Modified: 26 Feb 2026

    Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54190

    Last Modified: 13 Aug 2025

    Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54191

    Last Modified: 13 Aug 2025

    Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54195

    Last Modified: 13 Aug 2025

    Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54189

    Last Modified: 13 Aug 2025

    Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54192

    Last Modified: 13 Aug 2025

    Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49573

    Last Modified: 26 Feb 2026

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49572

    Last Modified: 26 Feb 2026

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54197

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54186

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54235

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54203

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54200

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54204

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49571

    Last Modified: 26 Feb 2026

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses an uncontrolled search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not require user interaction.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54202

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54199

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54201

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-54198

    Last Modified: 13 Aug 2025

    Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49570

    Last Modified: 26 Feb 2026

    Photoshop Desktop versions 25.12.3, 26.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-49562

    Last Modified: 14 Aug 2025

    Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49561

    Last Modified: 26 Feb 2026

    Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.5
    High

    CVE-2025-55171

    Last Modified: 14 Aug 2025

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, the application does not check authentication at endpoint /html/personalizacao_remover.php allowing anonymous attacker (without login) to delete any Image files at endpoint /html/personalizacao_remover.php by defining imagem_0 as image id to delete. This issue has been patched in version 3.4.8.

    Published: 12 Aug 2025