CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-6632

    Last Modified: 13 Nov 2025

    A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-47908

    Last Modified: 15 Apr 2026

    Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue load on the middleware/server as an attempt to cause a denial of service.

    Published: 6 Aug 2025
    9.3
    Critical

    CVE-2025-7768

    Last Modified: 15 Apr 2026

    Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges and take full control of the device, potentially modifying system settings, disrupting solar energy production, and interfering with safety mechanisms.

    Published: 6 Aug 2025
    3.5
    Low

    CVE-2025-38746

    Last Modified: 18 Aug 2025

    Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-38747

    Last Modified: 26 Feb 2026

    Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.

    Published: 6 Aug 2025
    2.1
    Low

    CVE-2025-8667

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2. Affected is the function from_code/from_dict/from_mcp of the file src/tools/tools.py. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Aug 2025
    2.1
    Low

    CVE-2025-8665

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the function MCPTools/MultiMCPTools in the library libs/agno/agno/tools/mcp.py of the component Model Context Protocol Handler. The manipulation of the argument command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Aug 2025
    5.4
    Medium

    CVE-2025-20215

    Last Modified: 15 Apr 2026

    A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provided the requisite conditions were satisfied. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vulnerability existed due to client certificate validation issues. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by monitoring local wireless or adjacent networks for client-join requests and attempting to interrupt and complete the meeting-join flow as another user who was currently joining a meeting. To successfully exploit the vulnerability, an attacker would need the capability to position themselves in a local wireless or adjacent network, to monitor and intercept the targeted network traffic flows, and to satisfy timing requirements in order to interrupt the meeting-join flow and exploit the vulnerability. A successful exploit could have allowed the attacker to join the meeting as another user. However, the Cisco Product Security Incident Response Team (PSIRT) is not aware of any malicious use of the vulnerability that is described in this advisory.

    Published: 6 Aug 2025
    4.3
    Medium

    CVE-2025-20332

    Last Modified: 15 Apr 2026

    A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on a specific page. To exploit this vulnerability, an attacker would need valid read-only Administrator credentials.

    Published: 6 Aug 2025
    5.4
    Medium

    CVE-2025-20331

    Last Modified: 15 Apr 2026

    A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on the affected device.

    Published: 6 Aug 2025
    8
    High

    CVE-2025-53786

    Last Modified: 15 Jun 2026

    On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.

    Published: 6 Aug 2025
    3.7
    Low

    CVE-2024-8244

    Last Modified: 15 Apr 2026

    The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.

    Published: 6 Aug 2025
    4.7
    Medium

    CVE-2025-48394

    Last Modified: 15 Apr 2026

    An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the CLI. This security issue has been fixed in the latest version which is available on the Eaton download center.

    Published: 6 Aug 2025
    5.7
    Medium

    CVE-2025-48393

    Last Modified: 15 Apr 2026

    The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton G4 PDU which is available on the Eaton download center.

    Published: 6 Aug 2025
    5
    Medium

    CVE-2024-52885

    Last Modified: 27 Aug 2025

    The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.

    Published: 6 Aug 2025
    6.5
    Medium

    CVE-2025-2028

    Last Modified: 27 Aug 2025

    Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

    Published: 6 Aug 2025
    5.9
    Medium

    CVE-2025-36020

    Last Modified: 22 Oct 2025

    IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential information.

    Published: 6 Aug 2025
    6.1
    Medium

    CVE-2025-8616

    Last Modified: 15 Apr 2026

    A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process to bypass Authentication. This issue affects Advanced Authentication on or before 6.5.0.

    Published: 6 Aug 2025
    8.1
    High

    CVE-2025-3354

    Last Modified: 26 Feb 2026

    IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.

    Published: 6 Aug 2025
    8.1
    High

    CVE-2025-3320

    Last Modified: 13 Aug 2025

    IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.

    Published: 6 Aug 2025
    4.4
    Medium

    CVE-2025-23335

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker could cause an underflow by a specific model configuration and a specific input. A successful exploit of this vulnerability might lead to denial of service.

    Published: 6 Aug 2025
    5.9
    Medium

    CVE-2025-23334

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by sending a request. A successful exploit of this vulnerability might lead to information disclosure.

    Published: 6 Aug 2025
    5.9
    Medium

    CVE-2025-23333

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by manipulating shared memory data. A successful exploit of this vulnerability might lead to information disclosure.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-23331

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive size value, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability might lead to denial of service.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-23327

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through specially crafted inputs. A successful exploit of this vulnerability might lead to denial of service and data tampering.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-23326

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-23325

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled recursion through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-23324

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability might lead to denial of service.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-23323

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability might lead to denial of service.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-23322

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a double free when a stream is cancelled before it is processed. A successful exploit of this vulnerability might lead to denial of service.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-23321

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero issue by issuing an invalid request. A successful exploit of this vulnerability might lead to denial of service.

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-23320

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause the shared memory limit to be exceeded by sending a very large request. A successful exploit of this vulnerability might lead to information disclosure.

    Published: 6 Aug 2025
    8.1
    High

    CVE-2025-23319

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write by sending a request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.

    Published: 6 Aug 2025
    8.1
    High

    CVE-2025-23318

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.

    Published: 6 Aug 2025
    9.1
    Critical

    CVE-2025-23317

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.

    Published: 6 Aug 2025
    9.8
    Critical

    CVE-2025-23311

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP requests. A successful exploit of this vulnerability might lead to remote code execution, denial of service, information disclosure, or data tampering.

    Published: 6 Aug 2025
    9.8
    Critical

    CVE-2025-23310

    Last Modified: 12 Aug 2025

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by specially crafted inputs. A successful exploit of this vulnerability might lead to remote code execution, denial of service, information disclosure, and data tampering.

    Published: 6 Aug 2025
    5.3
    Medium

    CVE-2025-5197

    Last Modified: 21 Oct 2025

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names to PyTorch format, uses a regex pattern `/[^/]*___([^/]*)/` that can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. The vulnerability affects versions up to 4.51.3 and is fixed in version 4.53.0. This issue can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting model conversion processes between TensorFlow and PyTorch formats.

    Published: 6 Aug 2025
    6.5
    Medium

    CVE-2025-46391

    Last Modified: 15 Apr 2026

    CWE-284: Improper Access Control

    Published: 6 Aug 2025
    7.5
    High

    CVE-2025-46390

    Last Modified: 15 Apr 2026

    CWE-204: Observable Response Discrepancy

    Published: 6 Aug 2025
    6.5
    Medium

    CVE-2025-46389

    Last Modified: 15 Apr 2026

    CWE-620: Unverified Password Change

    Published: 6 Aug 2025
    4.3
    Medium

    CVE-2025-46388

    Last Modified: 15 Apr 2026

    CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

    Published: 6 Aug 2025
    8.8
    High

    CVE-2025-46387

    Last Modified: 15 Apr 2026

    CWE-639 Authorization Bypass Through User-Controlled Key

    Published: 6 Aug 2025
    8.8
    High

    CVE-2025-46386

    Last Modified: 15 Apr 2026

    CWE-639 Authorization Bypass Through User-Controlled Key

    Published: 6 Aug 2025
    6.5
    Medium

    CVE-2025-6013

    Last Modified: 26 Feb 2026

    Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.

    Published: 6 Aug 2025
    9.3
    Critical

    CVE-2025-22470

    Last Modified: 15 Apr 2026

    CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrary Lua script may be executed on the system with the root privilege.

    Published: 6 Aug 2025
    6.9
    Medium

    CVE-2025-22469

    Last Modified: 15 Apr 2026

    OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1. An arbitrary OS command may be executed on the system with a certain non-administrative user privilege.

    Published: 6 Aug 2025
    8.7
    High

    CVE-2025-7771

    Last Modified: 15 Apr 2026

    ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbitrary code in kernel context, resulting in privilege escalation and potential follow-on attacks, such as disabling security software or bypassing kernel-level protections. ThrottleStop.sys version 3.0.0.0 and possibly others are affected. Apply updates per vendor instructions.

    Published: 6 Aug 2025
    5.3
    Medium

    CVE-2025-8620

    Last Modified: 21 Apr 2026

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id. CVE-2025-47444 is a duplicate of this issue. CVE-2025-47444 is a duplicate of this issue.

    Published: 6 Aug 2025
    3.7
    Low

    CVE-2025-8556

    Last Modified: 15 Apr 2026

    A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

    Published: 6 Aug 2025