CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-37881

    Last Modified: 12 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() The variable d->name, returned by devm_kasprintf(), could be NULL. A pointer check is added to prevent potential NULL pointer dereference. This is similar to the fix in commit 3027e7b15b02 ("ice: Fix some null pointer dereference issues in ice_ptp.c"). This issue is found by our static analysis tool

    Published: 9 May 2025
    7.8
    High

    CVE-2025-37882

    Last Modified: 2 Jan 2026

    In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix isochronous Ring Underrun/Overrun event handling The TRB pointer of these events points at enqueue at the time of error occurrence on xHCI 1.1+ HCs or it's NULL on older ones. By the time we are handling the event, a new TD may be queued at this ring position. I can trigger this race by rising interrupt moderation to increase IRQ handling delay. Similar delay may occur naturally due to system load. If this ever happens after a Missed Service Error, missed TDs will be skipped and the new TD processed as if it matched the event. It could be given back prematurely, risking data loss or buffer UAF by the xHC. Don't complete TDs on xrun events and don't warn if queued TDs don't match the event's TRB pointer, which can be NULL or a link/no-op TRB. Don't warn if there are no queued TDs at all. Now that it's safe, also handle xrun events if the skip flag is clear. This ensures completion of any TD stuck in 'error mid TD' state right before the xrun event, which could happen if a driver submits a finite number of URBs to a buggy HC and then an error occurs on the last TD.

    Published: 9 May 2025
    9.8
    Critical

    CVE-2025-45513

    Last Modified: 24 May 2025

    Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.

    Published: 9 May 2025
    9.8
    Critical

    CVE-2025-45885

    Last Modified: 28 May 2025

    PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.

    Published: 9 May 2025
    9.1
    Critical

    CVE-2025-45887

    Last Modified: 12 Jun 2025

    Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.

    Published: 9 May 2025
    9.8
    Critical

    CVE-2025-46188

    Last Modified: 22 May 2025

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.

    Published: 9 May 2025
    9.8
    Critical

    CVE-2025-46191

    Last Modified: 22 May 2025

    Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload executable PHP files to a web-accessible directory (/files/). This allows them to execute arbitrary commands remotely by accessing the uploaded script, resulting in full Remote Code Execution (RCE) without authentication.

    Published: 9 May 2025
    9.8
    Critical

    CVE-2025-46192

    Last Modified: 22 May 2025

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.

    Published: 9 May 2025
    9.8
    Critical

    CVE-2025-46193

    Last Modified: 22 May 2025

    SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.

    Published: 9 May 2025
    5.5
    Medium

    CVE-2025-37841

    Last Modified: 2 Jan 2026

    In the Linux kernel, the following vulnerability has been resolved: pm: cpupower: bench: Prevent NULL dereference on malloc failure If malloc returns NULL due to low memory, 'config' pointer can be NULL. Add a check to prevent NULL dereference.

    Published: 9 May 2025
    5.9
    Medium

    CVE-2025-4382

    Last Modified: 30 Jun 2026

    A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. If an attacker with physical access can corrupt the underlying filesystem superblock, GRUB will fail to locate a valid filesystem and enter rescue mode. At this point, the disk is already decrypted, and the decryption key remains loaded in system memory. This scenario may allow an attacker with physical access to access the unencrypted data without any further authentication, thereby compromising data confidentiality. Furthermore, the ability to force this state through filesystem corruption also presents a data integrity concern.

    Published: 8 May 2025
    5.3
    Medium

    CVE-2025-4443

    Last Modified: 13 May 2025

    A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 8 May 2025
    8.7
    High

    CVE-2025-4442

    Last Modified: 13 May 2025

    A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetWAN_Wizard55. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 8 May 2025
    8.7
    High

    CVE-2025-4441

    Last Modified: 13 May 2025

    A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formSetWAN_Wizard534. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 8 May 2025
    8.6
    High

    CVE-2025-4440

    Last Modified: 15 Apr 2026

    A vulnerability was found in H3C GR-1800AX up to 100R008 and classified as critical. Affected by this issue is the function EnableIpv6 of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used.

    Published: 8 May 2025
    9.3
    Critical

    CVE-2025-27720

    Last Modified: 15 Apr 2026

    The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials.

    Published: 8 May 2025
    6.9
    Medium

    CVE-2025-31946

    Last Modified: 15 Apr 2026

    Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause memory corruption or a system crash.

    Published: 8 May 2025
    8.7
    High

    CVE-2025-27578

    Last Modified: 15 Apr 2026

    Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition.

    Published: 8 May 2025
    8.7
    High

    CVE-2025-47732

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

    Published: 8 May 2025
    9.1
    Critical

    CVE-2025-47733

    Last Modified: 13 Feb 2026

    Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

    Published: 8 May 2025
    10
    Critical

    CVE-2025-29813

    Last Modified: 26 Feb 2026

    Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

    Published: 8 May 2025
    9.9
    Critical

    CVE-2025-29827

    Last Modified: 13 Feb 2026

    Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

    Published: 8 May 2025
    9.9
    Critical

    CVE-2025-29972

    Last Modified: 26 Feb 2026

    Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.

    Published: 8 May 2025
    8.1
    High

    CVE-2025-33072

    Last Modified: 13 Feb 2026

    Improper access control in Azure allows an unauthorized attacker to disclose information over a network.

    Published: 8 May 2025
    7.8
    High

    CVE-2025-1331

    Last Modified: 26 Feb 2026

    IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.

    Published: 8 May 2025
    7.8
    High

    CVE-2025-1330

    Last Modified: 26 Feb 2026

    IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyname function.

    Published: 8 May 2025
    7.8
    High

    CVE-2025-1329

    Last Modified: 26 Feb 2026

    IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyaddr function.

    Published: 8 May 2025
    Unknown

    CVE-2025-4475

    Last Modified: 8 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 May 2025
    4.6
    Medium

    CVE-2025-46833

    Last Modified: 15 Apr 2026

    Programs/P73_SimplePythonEncryption.py illustrates a simple Python encryption example using the RSA Algorithm. In versions prior to commit 6ce60b1, an attacker may be able to decrypt the data using brute force attacks and because of this the whole application can be impacted. This issue has been patched in commit 6ce60b1. A workaround involves increasing the key size, for RSA or DSA this is at least 2048 bits, for ECC this is at least 256 bits.

    Published: 8 May 2025
    2
    Low

    CVE-2025-46812

    Last Modified: 15 Apr 2026

    Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session, potentially leading to unauthorized actions being performed or sensitive information being disclosed. This issue has been patched in version 2.1.15.

    Published: 8 May 2025
    3.7
    Low

    CVE-2025-46712

    Last Modified: 15 Apr 2026

    Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25), Erlang/OTP SSH fails to enforce strict KEX handshake hardening measures by allowing optional messages to be exchanged. This allows a Man-in-the-Middle attacker to inject these messages in a connection during the handshake. This issue has been patched in versions OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25).

    Published: 8 May 2025
    4.2
    Medium

    CVE-2025-46336

    Last Modified: 15 Apr 2026

    Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), the session may be restored if the attacker can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout. This issue has been patched in version 2.1.1.

    Published: 8 May 2025
    7.5
    High

    CVE-2024-9448

    Last Modified: 15 Apr 2026

    On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in place. This could lead to packets being delivered to unexpected destinations.

    Published: 8 May 2025
    4.9
    Medium

    CVE-2025-27695

    Last Modified: 13 Jul 2025

    Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.

    Published: 8 May 2025
    9.1
    Critical

    CVE-2024-12378

    Last Modified: 15 Apr 2026

    On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.

    Published: 8 May 2025
    10
    Critical

    CVE-2024-11186

    Last Modified: 15 Apr 2026

    On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact CloudVision as-a-Service.

    Published: 8 May 2025
    10
    Critical

    CVE-2025-0505

    Last Modified: 15 Apr 2026

    On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under management. Note that CloudVision as-a-Service is not affected.

    Published: 8 May 2025
    8.7
    High

    CVE-2024-8100

    Last Modified: 15 Apr 2026

    On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.

    Published: 8 May 2025
    7.5
    High

    CVE-2025-1948

    Last Modified: 31 Jul 2025

    In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thrown, or even the JVM process exiting.

    Published: 8 May 2025
    8.4
    High

    CVE-2025-4098

    Last Modified: 15 Apr 2026

    Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could allow an attacker to disclose information and execute arbitrary code on affected installations of Cscape.

    Published: 8 May 2025
    4.4
    Medium

    CVE-2025-30101

    Last Modified: 16 May 2025

    Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to denial of service and information tampering.

    Published: 8 May 2025
    5.5
    Medium

    CVE-2025-30102

    Last Modified: 16 May 2025

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.

    Published: 8 May 2025
    Unknown

    CVE-2025-4438

    Last Modified: 7 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 May 2025
    Unknown

    CVE-2025-4436

    Last Modified: 20 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 May 2025
    Unknown

    CVE-2025-4132

    Last Modified: 12 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 May 2025
    5.9
    Medium

    CVE-2025-4207

    Last Modified: 15 Apr 2026

    Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

    Published: 8 May 2025
    7.2
    High

    CVE-2024-13009

    Last Modified: 31 Jul 2025

    In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.

    Published: 8 May 2025
    8.7
    High

    CVE-2024-6648

    Last Modified: 13 May 2025

    Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.

    Published: 8 May 2025
    6.3
    Medium

    CVE-2025-3506

    Last Modified: 25 Aug 2025

    Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets.

    Published: 8 May 2025
    6.1
    Medium

    CVE-2025-2806

    Last Modified: 21 Apr 2026

    The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 8 May 2025