CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-3381

    Last Modified: 10 Oct 2025

    A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMController.java of the component File Upload. The manipulation of the argument ID leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3380

    Last Modified: 23 Apr 2025

    A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. Affected by this issue is some unknown functionality of the component FEAT Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3379

    Last Modified: 29 Apr 2025

    A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. Affected by this vulnerability is an unknown functionality of the component EPSV Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3378

    Last Modified: 23 Apr 2025

    A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component EPRT Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3377

    Last Modified: 16 May 2025

    A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component ENC Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    4.6
    Medium

    CVE-2024-38797

    Last Modified: 15 Apr 2026

    EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3376

    Last Modified: 16 May 2025

    A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component CONF Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3375

    Last Modified: 16 May 2025

    A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component CDUP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    7.2
    High

    CVE-2025-3426

    Last Modified: 15 Apr 2026

    We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result, attackers can reverse-engineer the application to gain insights into its internal workings, which can potentially lead to the discovery of sensitive information, business logic flaws, and other vulnerabilities. Utilizing this flaw, the attacker was able to identify the Hardcoded credentials from PortalUsersDatabase.dll, which contains .NET remoting definition. Inside the namespace PortalUsersDatabase, the class Users contains the functions CreateAdmin and CreateService that are used to initialize accounts in the Portal service. Both CreateAdmin and CreateService functions contain a hardcoded encrypted password along with its respective salt that are set with the function SetInitialPasswordAndSalt. This issue affects IntelliSpace Portal: 12 and prior; Advanced Visualization Workspace: 15.

    Published: 7 Apr 2025
    7.3
    High

    CVE-2025-3425

    Last Modified: 15 Apr 2026

    The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is dangerous as it can potentially lead to remote code execution using deserialization. This issue affects IntelliSpace Portal: 12 and prior.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3374

    Last Modified: 23 Apr 2025

    A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    7.7
    High

    CVE-2025-3424

    Last Modified: 15 Apr 2026

    The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific .NET Remoting URLs derived from information enumerated in the client-side configuration files. This issue affects IntelliSpace Portal: 12 and prior.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3373

    Last Modified: 16 May 2025

    A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component SITE CHMOD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3372

    Last Modified: 16 May 2025

    A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-32014

    Last Modified: 15 Apr 2026

    estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.

    Published: 7 Apr 2025
    4.8
    Medium

    CVE-2025-31476

    Last Modified: 4 Sept 2025

    tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to execution of arbitrary JavaScript code, theft of sensitive data through phishing attacks, or modification of the user interface behavior. This vulnerability is fixed in 1.20.1.

    Published: 7 Apr 2025
    5.5
    Medium

    CVE-2025-31475

    Last Modified: 21 Oct 2025

    tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution. An attacker with high privileges could exploit this vulnerability to modify object prototypes, affecting core JavaScript behavior, cause application crashes or unexpected behavior, or potentially introduce further security vulnerabilities depending on the application's architecture. This vulnerability is fixed in 1.20.1.

    Published: 7 Apr 2025
    5.5
    Medium

    CVE-2025-31138

    Last Modified: 21 Oct 2025

    tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set values like 100%;height:100%;position:fixed;, potentially covering the entire viewport and facilitating clickjacking attacks. An attacker with high privileges could exploit this vulnerability to overlay malicious UI elements on top of legitimate content, trick users into interacting with hidden elements (clickjacking), or disrupt the intended functionality and accessibility of the website. This vulnerability is fixed in 1.20.1.

    Published: 7 Apr 2025
    6.5
    Medium

    CVE-2025-30373

    Last Modified: 30 Oct 2025

    Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. To mitigate the vulnerability, disable http-based inputs and allow only authenticated pull-based inputs. This vulnerability is fixed in 6.1.9.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3371

    Last Modified: 16 May 2025

    A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    9.8
    Critical

    CVE-2025-3248

    Last Modified: 29 Nov 2025

    Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3370

    Last Modified: 7 May 2025

    A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 7 Apr 2025
    5.3
    Medium

    CVE-2025-3369

    Last Modified: 10 Oct 2025

    A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /novel/friendLink/list. The manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2025-30195

    Last Modified: 15 Apr 2026

    An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patched 5.2.1 version. We would like to thank Volodymyr Ilyin for bringing this issue to our attention.

    Published: 7 Apr 2025
    2.7
    Low

    CVE-2025-27686

    Last Modified: 12 Jan 2026

    Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3353

    Last Modified: 11 Apr 2025

    A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/add-services.php. The manipulation of the argument cost leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3352

    Last Modified: 7 May 2025

    A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-scdetails.php. The manipulation of the argument contnum leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    5.9
    Medium

    CVE-2025-0050

    Last Modified: 18 Dec 2025

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to make valid GPU processing operations, including via WebGL or WebGPU, to access a limited amount outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r0p0 through r49p2, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r19p0 through r49p2, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p2, from r50p0 through r53p0.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3351

    Last Modified: 7 May 2025

    A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3350

    Last Modified: 7 May 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/view-enquiry.php. The manipulation of the argument viewid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    6.9
    Medium

    CVE-2025-3349

    Last Modified: 16 May 2025

    A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SYST Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    5.3
    Medium

    CVE-2025-3348

    Last Modified: 28 May 2025

    A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerability affects unknown code of the file /edit_dpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2025-21448

    Last Modified: 6 Oct 2025

    Transient DOS may occur while parsing SSID in action frames.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21447

    Last Modified: 26 Feb 2026

    Memory corruption may occur while processing device IO control call for session control.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21443

    Last Modified: 26 Feb 2026

    Memory corruption while processing message content in eAVB.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21442

    Last Modified: 26 Feb 2026

    Memory corruption while transmitting packet mapping information with invalid header payload size.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21441

    Last Modified: 26 Feb 2026

    Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21440

    Last Modified: 26 Feb 2026

    Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21439

    Last Modified: 26 Feb 2026

    Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21438

    Last Modified: 26 Feb 2026

    Memory corruption while IOCTL call is invoked from user-space to read board data.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21437

    Last Modified: 26 Feb 2026

    Memory corruption while processing memory map or unmap IOCTL operations simultaneously.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21436

    Last Modified: 26 Feb 2026

    Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2025-21435

    Last Modified: 6 Oct 2025

    Transient DOS may occur while parsing extended IE in beacon.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2025-21434

    Last Modified: 6 Oct 2025

    Transient DOS may occur while parsing EHT operation IE or EHT capability IE.

    Published: 7 Apr 2025
    5.5
    Medium

    CVE-2025-21431

    Last Modified: 19 Aug 2025

    Information disclosure may be there when a guest VM is connected.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2025-21430

    Last Modified: 6 Oct 2025

    Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2025-21429

    Last Modified: 26 Feb 2026

    Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.

    Published: 7 Apr 2025
    7.5
    High

    CVE-2025-21428

    Last Modified: 26 Feb 2026

    Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.

    Published: 7 Apr 2025
    7.3
    High

    CVE-2025-21425

    Last Modified: 26 Feb 2026

    Memory corruption may occur due top improper access control in HAB process.

    Published: 7 Apr 2025
    7.8
    High

    CVE-2025-21423

    Last Modified: 26 Feb 2026

    Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.

    Published: 7 Apr 2025