CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2025-43243

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.

    Published: 29 Jul 2025
    9.8
    Critical

    CVE-2025-43193

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause a denial-of-service.

    Published: 29 Jul 2025
    9.8
    Critical

    CVE-2025-31279

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to fingerprint the user.

    Published: 29 Jul 2025
    7.1
    High

    CVE-2025-43239

    Last Modified: 28 Apr 2026

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Processing a maliciously crafted file may lead to unexpected app termination.

    Published: 29 Jul 2025
    9.1
    Critical

    CVE-2025-31281

    Last Modified: 28 Apr 2026

    An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted file may lead to unexpected app termination.

    Published: 29 Jul 2025
    9.8
    Critical

    CVE-2025-43192

    Last Modified: 28 Apr 2026

    A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. Account-driven User Enrollment may still be possible with Lockdown Mode turned on.

    Published: 29 Jul 2025
    7.1
    High

    CVE-2025-43254

    Last Modified: 28 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Processing a maliciously crafted file may lead to unexpected app termination.

    Published: 29 Jul 2025
    9.8
    Critical

    CVE-2025-43184

    Last Modified: 28 Apr 2026

    This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A shortcut may be able to bypass sensitive Shortcuts app settings.

    Published: 29 Jul 2025
    5.5
    Medium

    CVE-2025-43235

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-service.

    Published: 29 Jul 2025
    4.4
    Medium

    CVE-2025-43274

    Last Modified: 28 Apr 2026

    A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to circumvent sandbox restrictions.

    Published: 29 Jul 2025
    7.5
    High

    CVE-2025-43223

    Last Modified: 2 Apr 2026

    A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. A non-privileged user may be able to modify restricted network settings.

    Published: 29 Jul 2025
    9.9
    Critical

    CVE-2025-54381

    Last Modified: 5 Aug 2025

    BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to force the server to make arbitrary HTTP requests. The vulnerability stems from the multipart form data and JSON request handlers, which automatically download files from user-provided URLs without validating whether those URLs point to internal network addresses, cloud metadata endpoints, or other restricted resources. The documentation explicitly promotes this URL-based file upload feature, making it an intended design that exposes all deployed services to SSRF attacks by default. Version 1.4.19 contains a patch for the issue.

    Published: 29 Jul 2025
    6.9
    Medium

    CVE-2025-54126

    Last Modified: 23 Sept 2025

    The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. In versions 2.4.0 and below, iwasm uses --addr-pool with an IPv4 address that lacks a subnet mask, allowing the system to accept all IP addresses. This can unintentionally expose the service to all incoming connections and bypass intended access restrictions. Services relying on --addr-pool for restricting access by IP may unintentionally become open to all external connections. This may lead to unauthorized access in production deployments, especially when users assume that specifying an IP without a subnet mask implies a default secure configuration. This is fixed in version 2.4.1.

    Published: 29 Jul 2025
    8.5
    High

    CVE-2025-7849

    Last Modified: 26 Feb 2026

    A memory corruption vulnerability due to improper error handling when a VILinkObj is null exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.

    Published: 29 Jul 2025
    8.5
    High

    CVE-2025-7848

    Last Modified: 26 Feb 2026

    A memory corruption vulnerability due to improper input validation in lvpict.cpp exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.

    Published: 29 Jul 2025
    8.5
    High

    CVE-2025-7361

    Last Modified: 26 Feb 2026

    A code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI using a CIN node. This vulnerability affects 32-bit NI LabVIEW 2025 Q1 and prior versions. LabVIEW 64-bit versions do not support CIN nodes and are not affected.

    Published: 29 Jul 2025
    8.6
    High

    CVE-2025-4674

    Last Modified: 29 Jan 2026

    The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

    Published: 29 Jul 2025
    9.8
    Critical

    CVE-2025-40600

    Last Modified: 11 Aug 2025

    Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-5684

    Last Modified: 21 Apr 2026

    The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `mf-template` DOM Element in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jul 2025
    4.3
    Medium

    CVE-2025-53902

    Last Modified: 22 Aug 2025

    Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not authorized to view. This is fixed in Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5.

    Published: 29 Jul 2025
    5.4
    Medium

    CVE-2025-53541

    Last Modified: 5 Aug 2025

    Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3, malicious users with some control over certain artifacts could insert malicious code when displaying the children of a parent artifact to force victims to execute the uncontrolled code. This is fixed in version Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3.

    Published: 29 Jul 2025
    8.2
    High

    CVE-2025-53102

    Last Modified: 31 Jul 2025

    Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, which the client signs. The challenge is not cleared from the user’s session after authentication, potentially allowing reuse and increasing security risk. This is fixed in versions 3.4.7 and 3.5.0.beta.8.

    Published: 29 Jul 2025
    5.3
    Medium

    CVE-2025-52899

    Last Modified: 22 Aug 2025

    Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1750843170 and Tuleap Enterprise Edition prior to 16.8-4 and 16.9-2, the forgot password form allows for user enumeration. This is fixed in Tuleap Community Edition version 16.9.99.1750843170 and Tuleap Enterprise Edition 16.8-4 and 16.9-2.

    Published: 29 Jul 2025
    6.5
    Medium

    CVE-2024-49828

    Last Modified: 17 Aug 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

    Published: 29 Jul 2025
    6.5
    Medium

    CVE-2024-51473

    Last Modified: 17 Aug 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

    Published: 29 Jul 2025
    4.9
    Medium

    CVE-2024-52894

    Last Modified: 17 Aug 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

    Published: 29 Jul 2025
    5.3
    Medium

    CVE-2025-33114

    Last Modified: 6 Aug 2025

    IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially crafted query under certain non-default conditions.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-33092

    Last Modified: 26 Feb 2026

    IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

    Published: 29 Jul 2025
    6.5
    Medium

    CVE-2025-36071

    Last Modified: 7 Aug 2025

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query due to improper release of memory resources.

    Published: 29 Jul 2025
    6.5
    Medium

    CVE-2025-36010

    Last Modified: 6 Aug 2025

    IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial of service due to executable segments that are waiting for each other to release a necessary lock.

    Published: 29 Jul 2025
    6.9
    Medium

    CVE-2025-53715

    Last Modified: 1 Aug 2025

    A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 29 Jul 2025
    6.9
    Medium

    CVE-2025-53714

    Last Modified: 1 Aug 2025

    A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 29 Jul 2025
    6.9
    Medium

    CVE-2025-53713

    Last Modified: 1 Aug 2025

    A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 29 Jul 2025
    6.9
    Medium

    CVE-2025-53712

    Last Modified: 1 Aug 2025

    A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-7675

    Last Modified: 8 May 2026

    A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 29 Jul 2025
    6.9
    Medium

    CVE-2025-53711

    Last Modified: 19 Mar 2026

    A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the /userRpm/WlanNetworkRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a crash of the web service and result in a denial-of-service (DoS) condition. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-7497

    Last Modified: 8 May 2026

    A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-6637

    Last Modified: 8 May 2026

    A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-6636

    Last Modified: 8 May 2026

    A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-6635

    Last Modified: 8 May 2026

    A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-6631

    Last Modified: 8 May 2026

    A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-5043

    Last Modified: 4 May 2026

    A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Jul 2025
    7.8
    High

    CVE-2025-5038

    Last Modified: 8 May 2026

    A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

    Published: 29 Jul 2025
    7.2
    High

    CVE-2025-2928

    Last Modified: 15 Apr 2026

    SQL Injection affecting the Archiver role.

    Published: 29 Jul 2025
    5.3
    Medium

    CVE-2025-2533

    Last Modified: 6 Aug 2025

    IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

    Published: 29 Jul 2025
    4.5
    Medium

    CVE-2025-27514

    Last Modified: 4 Aug 2025

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through 10.0.18, a technician can use a malicious payload to trigger a stored XSS on the project's kanban. This is fixed in version 10.0.19.

    Published: 29 Jul 2025
    6.8
    Medium

    CVE-2025-2179

    Last Modified: 15 Apr 2026

    An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The GlobalProtect app on Windows, macOS, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

    Published: 29 Jul 2025
    4.8
    Medium

    CVE-2025-5922

    Last Modified: 15 Apr 2026

    Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's hash is stored in a system registry accessible to regular users, making it possible to perform a brute-force attack using rainbow tables, since the hash is not salted. LTS (Long-Term Support) versions also received patches in v17.2025.6.27 and v16.2025.6.27 releases.

    Published: 29 Jul 2025
    8.2
    High

    CVE-2025-31965

    Last Modified: 15 Apr 2026

    Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages.

    Published: 29 Jul 2025
    Unknown

    CVE-2025-54797

    Last Modified: 5 Aug 2025

    This CVE is a duplicate of CVE-2025-52464.

    Published: 29 Jul 2025