CVE Feed

    Dashboard / CVE

    1.9
    Low

    CVE-2025-8842

    Last Modified: 15 Sept 2025

    A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8841

    Last Modified: 16 Sept 2025

    A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8840

    Last Modified: 9 Sept 2025

    A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of the argument ids leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Different than CVE-2025-7947.

    Published: 11 Aug 2025
    9.3
    Critical

    CVE-2025-8853

    Last Modified: 15 Apr 2026

    Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8839

    Last Modified: 9 Sept 2025

    A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025
    5.5
    Medium

    CVE-2025-8838

    Last Modified: 11 Sept 2025

    A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHandle of the file /admin/ of the component Backend Interface. The manipulation of the argument uri leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The code maintainer responded to the issue that "[he] tried it, and using this link automatically redirects to the login page."

    Published: 11 Aug 2025
    1.9
    Low

    CVE-2025-8837

    Last Modified: 16 Sept 2025

    A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named 8308060d3fbc1da10353ac8a95c8ea60eba9c25a. It is recommended to apply a patch to fix this issue.

    Published: 11 Aug 2025
    4.6
    Medium

    CVE-2025-8661

    Last Modified: 16 Sept 2025

    A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user.

    Published: 11 Aug 2025
    1.9
    Low

    CVE-2025-8836

    Last Modified: 16 Sept 2025

    A vulnerability was determined in JasPer up to 4.2.5. Affected by this issue is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 Encoder. The manipulation leads to reachable assertion. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 79185d32d7a444abae441935b20ae4676b3513d4. It is recommended to apply a patch to fix this issue.

    Published: 11 Aug 2025
    8.6
    High

    CVE-2025-8747

    Last Modified: 26 Feb 2026

    A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive.

    Published: 11 Aug 2025
    5.6
    Medium

    CVE-2025-8660

    Last Modified: 16 Sept 2025

    Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.

    Published: 11 Aug 2025
    1.9
    Low

    CVE-2025-8835

    Last Modified: 16 Sept 2025

    A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of the patch is bb7d62bd0a2a8e0e1fdb4d603f3305f955158c52. It is recommended to apply a patch to fix this issue.

    Published: 11 Aug 2025
    1.9
    Low

    CVE-2025-8834

    Last Modified: 15 Apr 2026

    A vulnerability has been found in JCG Link-net LW-N915R 17s.20.001.908. Affected is an unknown function of the file /wireless/basic.asp of the component Wireless Basic Settings Page. The manipulation of the argument Network Name leads to cross site scripting. It is possible to launch the attack remotely.

    Published: 11 Aug 2025
    7.4
    High

    CVE-2025-8833

    Last Modified: 4 Sept 2025

    A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function langSwitchBack of the file /goform/langSwitchBack. The manipulation of the argument langSelectionOnly leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    4.3
    Medium

    CVE-2025-7965

    Last Modified: 15 Apr 2026

    The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 11 Aug 2025
    7.4
    High

    CVE-2025-8832

    Last Modified: 4 Sept 2025

    A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function setDMZ of the file /goform/setDMZ. The manipulation of the argument DMZIPAddress leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    7.4
    High

    CVE-2025-8831

    Last Modified: 4 Sept 2025

    A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function remoteManagement of the file /goform/remoteManagement. The manipulation of the argument portNumber leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8830

    Last Modified: 4 Sept 2025

    A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function sub_3517C of the file /goform/setWan. The manipulation of the argument Hostname leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    8.4
    High

    CVE-2025-8854

    Last Modified: 8 Dec 2025

    Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd function.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8829

    Last Modified: 4 Sept 2025

    A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of the file /goform/RP_setBasicAuto. The manipulation of the argument hname leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8828

    Last Modified: 4 Sept 2025

    A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function ipv6cmd of the file /goform/setIpv6. The manipulation of the argument Ipv6PriDns/Ipv6SecDns/Ipv6StaticGateway/LanIpv6Addr/LanPrefixLen/pppoeUser/pppoePass/pppoeIdleTime/pppoeRedialPeriod/Ipv6in4_PrefixLen/LocalIpv6/RemoteIpv4/LanIPv6_Prefix/LanPrefixLen/ipv6to4Relay/ipv6rdRelay/tunrd_PrefixLen/wan_UseLinkLocal/Ipv6StaticIp/Ipv6PrefixLen leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8827

    Last Modified: 4 Sept 2025

    A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function um_inspect_cross_band of the file /goform/RP_setBasicAuto. The manipulation of the argument staticGateway leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    3.3
    Low

    CVE-2025-27562

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

    Published: 11 Aug 2025
    8.4
    High

    CVE-2025-27128

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

    Published: 11 Aug 2025
    3.3
    Low

    CVE-2025-25212

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input.

    Published: 11 Aug 2025
    3.3
    Low

    CVE-2025-24844

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

    Published: 11 Aug 2025
    3.3
    Low

    CVE-2025-27536

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.

    Published: 11 Aug 2025
    3.3
    Low

    CVE-2025-26690

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

    Published: 11 Aug 2025
    3.3
    Low

    CVE-2025-24925

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

    Published: 11 Aug 2025
    8.4
    High

    CVE-2025-24298

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

    Published: 11 Aug 2025
    8.4
    High

    CVE-2025-25278

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

    Published: 11 Aug 2025
    8.4
    High

    CVE-2025-27577

    Last Modified: 12 Aug 2025

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

    Published: 11 Aug 2025
    7.4
    High

    CVE-2025-8826

    Last Modified: 4 Sept 2025

    A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function um_rp_autochannel of the file /goform/RP_setBasicAuto. The manipulation of the argument apcli_AuthMode_2G/apcli_AuthMode_5G leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8825

    Last Modified: 4 Sept 2025

    A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto of the file /goform/RP_setBasicAuto. The manipulation of the argument staticIp/staticNetmask leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    7.4
    High

    CVE-2025-8824

    Last Modified: 4 Sept 2025

    A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function setRIP of the file /goform/setRIP. The manipulation of the argument RIPmode/RIPpasswd leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8823

    Last Modified: 4 Sept 2025

    A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setDeviceName of the file /goform/setDeviceName. The manipulation of the argument DeviceName leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    7.4
    High

    CVE-2025-8822

    Last Modified: 4 Sept 2025

    A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function algDisable of the file /goform/setOpMode. The manipulation of the argument opMode leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8821

    Last Modified: 4 Sept 2025

    A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function RP_setBasic of the file /goform/RP_setBasic. The manipulation of the argument bssid leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 Aug 2025
    7.8
    High

    CVE-2025-38499

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns What we want is to verify there is that clone won't expose something hidden by a mount we wouldn't be able to undo. "Wouldn't be able to undo" may be a result of MNT_LOCKED on a child, but it may also come from lacking admin rights in the userns of the namespace mount belongs to. clone_private_mnt() checks the former, but not the latter. There's a number of rather confusing CAP_SYS_ADMIN checks in various userns during the mount, especially with the new mount API; they serve different purposes and in case of clone_private_mnt() they usually, but not always end up covering the missing check mentioned above.

    Published: 11 Aug 2025
    3.3
    Low

    CVE-2025-8860

    Last Modified: 15 Apr 2026

    A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANSFER, the .read callback `uefi_vars_read` returns leftover metadata or other sensitive process memory from the previously allocated buffer, leading to an information disclosure vulnerability.

    Published: 11 Aug 2025
    9.8
    Critical

    CVE-2025-45146

    Last Modified: 17 Oct 2025

    ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.

    Published: 11 Aug 2025
    6.5
    Medium

    CVE-2025-51823

    Last Modified: 14 Aug 2025

    libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parameter. The function uses strcpy to copy the interface name into a structure member (ctx->name) without validating the input length.

    Published: 11 Aug 2025
    6.5
    Medium

    CVE-2025-51824

    Last Modified: 14 Aug 2025

    libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.

    Published: 11 Aug 2025
    7.4
    High

    CVE-2025-8820

    Last Modified: 4 Sept 2025

    A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function wirelessBasic of the file /goform/wirelessBasic. The manipulation of the argument submit_SSID1 leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Aug 2025
    7.4
    High

    CVE-2025-8819

    Last Modified: 4 Sept 2025

    A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function setWan of the file /goform/setWan. The manipulation of the argument staticIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Aug 2025
    2.1
    Low

    CVE-2025-8818

    Last Modified: 4 Sept 2025

    A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function setDFSSetting of the file /goform/setLan. The manipulation of the argument lanNetmask/lanIp leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Aug 2025
    7.4
    High

    CVE-2025-8817

    Last Modified: 4 Sept 2025

    A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setLan of the file /goform/setLan. The manipulation of the argument lan2enabled leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Aug 2025
    7.4
    High

    CVE-2025-8816

    Last Modified: 4 Sept 2025

    A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function setOpMode of the file /goform/setOpMode. The manipulation of the argument ethConv leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Aug 2025
    5.5
    Medium

    CVE-2025-8815

    Last Modified: 16 Sept 2025

    A vulnerability was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. It has been classified as critical. Affected is an unknown function of the file /index of the component Shiro Configuration. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

    Published: 10 Aug 2025
    2.1
    Low

    CVE-2025-8814

    Last Modified: 2 Sept 2025

    A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function setCookie of the file src/main/java/co/yiiu/pybbs/util/CookieUtil.java. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 8aa2bb1aef3346e49aec6358edf5e47ce905ae7b. It is recommended to apply a patch to fix this issue.

    Published: 10 Aug 2025