CVE Feed

    Dashboard / CVE

    8.7
    High

    CVE-2023-34440

    Last Modified: 15 Apr 2026

    Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    8.7
    High

    CVE-2023-43758

    Last Modified: 15 Apr 2026

    Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    4.6
    Medium

    CVE-2024-26021

    Last Modified: 15 Apr 2026

    Improper initialization in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2024-30211

    Last Modified: 15 Apr 2026

    Improper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    7.1
    High

    CVE-2024-38307

    Last Modified: 15 Apr 2026

    Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authenticated user to potentially enable denial of service via network access.

    Published: 12 Feb 2025
    6.8
    Medium

    CVE-2024-21859

    Last Modified: 15 Apr 2026

    Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

    Published: 12 Feb 2025
    8.7
    High

    CVE-2024-31155

    Last Modified: 15 Apr 2026

    Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    5.7
    Medium

    CVE-2024-39779

    Last Modified: 15 Apr 2026

    Stack-based buffer overflow in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 12 Feb 2025
    5.7
    Medium

    CVE-2024-39797

    Last Modified: 15 Apr 2026

    Improper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 12 Feb 2025
    7.1
    High

    CVE-2024-36274

    Last Modified: 15 Apr 2026

    Out-of-bounds write in the Intel(R) 800 Series Ethernet Driver for Intel(R) Ethernet Adapter Complete Driver Pack before versions 29.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-24852

    Last Modified: 15 Apr 2026

    Uncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-36291

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some Intel(R) Chipset Software Installation Utility before version 10.1.19867.8574 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-32938

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some Intel(R) MPI Library for Windows software before version 2021.13 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-39284

    Last Modified: 2 Sept 2025

    Uncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-39813

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some EPCT software before version 1.42.8.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-41917

    Last Modified: 15 Apr 2026

    Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    2
    Low

    CVE-2024-39286

    Last Modified: 15 Apr 2026

    Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-42492

    Last Modified: 15 Apr 2026

    Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-21830

    Last Modified: 15 Apr 2026

    Uncontrolled search path in some Intel(R) VPL software before version 2023.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    4.1
    Medium

    CVE-2024-41934

    Last Modified: 15 Apr 2026

    Improper access control in some Intel(R) GPA software before version 2024.3 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-42419

    Last Modified: 15 Apr 2026

    Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    6.8
    Medium

    CVE-2024-42410

    Last Modified: 15 Apr 2026

    Improper input validation in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-38310

    Last Modified: 15 Apr 2026

    Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    8.5
    High

    CVE-2024-37355

    Last Modified: 15 Apr 2026

    Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    5.1
    Medium

    CVE-2024-31153

    Last Modified: 3 Dec 2025

    Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 12 Feb 2025
    4.3
    Medium

    CVE-2023-32277

    Last Modified: 15 Apr 2026

    Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.

    Published: 12 Feb 2025
    5.4
    Medium

    CVE-2024-29223

    Last Modified: 3 Dec 2025

    Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    7.3
    High

    CVE-2024-31858

    Last Modified: 26 Feb 2026

    Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-0113

    Last Modified: 15 Apr 2026

    A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server.

    Published: 12 Feb 2025
    8.6
    High

    CVE-2025-0110

    Last Modified: 15 Apr 2026

    A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administrator with the ability to make gNMI requests to the PAN-OS management web interface to bypass system restrictions and run arbitrary commands. The commands are run as the “__openconfig” user (which has the Device Administrator role) on the firewall. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-1227

    Last Modified: 26 Aug 2025

    A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selectList of the file com/cloudweb/oa/mapper/xml/AddressDao.xml. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 12 Feb 2025
    7.1
    High

    CVE-2025-0111

    Last Modified: 26 Feb 2026

    An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

    Published: 12 Feb 2025
    6.9
    Medium

    CVE-2025-0109

    Last Modified: 15 Apr 2026

    An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

    Published: 12 Feb 2025
    8.8
    High

    CVE-2025-0108

    Last Modified: 26 Feb 2026

    An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software.

    Published: 12 Feb 2025
    8.5
    High

    CVE-2024-12673

    Last Modified: 15 Apr 2026

    An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices: * Lenovo V Series (Gen 5) * ThinkBook 14 (Gen 6, 7) * ThinkBook 16 (Gen 6, 7) * ThinkPad E Series (Gen 1)

    Published: 12 Feb 2025
    6.9
    Medium

    CVE-2025-1226

    Last Modified: 26 Aug 2025

    A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-1225

    Last Modified: 26 Aug 2025

    A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-1224

    Last Modified: 26 Aug 2025

    A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-1216

    Last Modified: 26 Aug 2025

    A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file com/cloudweb/oa/mapper/xml/OaNoticeMapper.xml. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 12 Feb 2025
    7.1
    High

    CVE-2025-0937

    Last Modified: 15 Dec 2025

    Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.

    Published: 12 Feb 2025
    2.4
    Low

    CVE-2025-1215

    Last Modified: 13 Aug 2025

    A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.

    Published: 12 Feb 2025
    8.1
    High

    CVE-2025-1146

    Last Modified: 15 Apr 2026

    CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection routine to the CrowdStrike cloud can incorrectly process server certificate validation. This could allow an attacker with the ability to control network traffic to potentially conduct a man-in-the-middle (MiTM) attack. CrowdStrike identified this issue internally and released a security fix in all Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor versions 7.06 and above. CrowdStrike identified this issue through our longstanding, rigorous security review process, which has been continually strengthened with deeper source code analysis and ongoing program enhancements as part of our commitment to security resilience. CrowdStrike has no indication of any exploitation of this issue in the wild. CrowdStrike has leveraged its world class threat hunting and intelligence capabilities to actively monitor for signs of abuse or usage of this flaw and will continue to do so. Windows and Mac sensors are not affected by this.

    Published: 12 Feb 2025
    7.5
    High

    CVE-2025-25283

    Last Modified: 15 Apr 2026

    parse-duraton is software that allows users to convert a human readable duration to milliseconds. Versions prior to 2.1.3 are vulnerable to an event loop delay due to the CPU-bound operation of resolving the provided string, from a 0.5ms and up to ~50ms per one operation, with a varying size from 0.01 MB and up to 4.3 MB respectively, and an out of memory that would crash a running Node.js application due to a string size of roughly 10 MB that utilizes unicode characters. Version 2.1.3 contains a patch.

    Published: 12 Feb 2025
    8.2
    High

    CVE-2025-25205

    Last Modified: 3 Jul 2025

    Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Attackers can craft URLs containing substrings like "/api/items/1/cover" in a query parameter (?r=/api/items/1/cover) to partially bypass authentication or trigger server crashes under certain routes. This could lead to information disclosure of otherwise protected data and, in some cases, a complete denial of service (server crash) if downstream code expects an authenticated user object. Version 2.19.1 contains a patch for the issue.

    Published: 12 Feb 2025
    4
    Medium

    CVE-2025-25201

    Last Modified: 15 Apr 2026

    Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled prior to 1.8.0, the PIV application could accept invalid keys for authentication of the admin key. This could lead to compromise of the integrity of the data stored in the application. An attacker without access to the proper administration key would be able to generate new keys and overwrite certificates. Such an attacker would not be able to read-out or extract existing private data, nor would they be able to gain access to cryptographic operations that would normally require PIN-based authentication. The issue is fixed in piv-authenticator 0.3.9, and in Nitrokey's firmware 1.8.1.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2025-1214

    Last Modified: 17 Oct 2025

    A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of the component Role-Based Access Control. The manipulation leads to missing authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Feb 2025
    9.2
    Critical

    CVE-2025-25200

    Last Modified: 20 Jan 2026

    Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the `X-Forwarded-Proto` and `X-Forwarded-Host` HTTP headers. This can be exploited to carry out a Denial-of-Service attack. Versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3 fix the issue.

    Published: 12 Feb 2025
    7.5
    High

    CVE-2025-25199

    Last Modified: 15 Apr 2026

    go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41, calls to `cng.TLS1PRF` don't release the key handle, producing a small memory leak every time. Commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41 contains a fix for the issue. The fix is included in versions 1.23.6-2 and 1.22.12-2 of the Microsoft build of go, as well as in the pseudoversion 0.0.0-20250211154640-f49c8e1379ea of the `github.com/microsoft/go-crypto-winnative` Go package.

    Published: 12 Feb 2025
    7.1
    High

    CVE-2025-25198

    Last Modified: 1 Oct 2025

    mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to manipulate the `Host HTTP` header to generate a password reset link pointing to an attacker-controlled domain. This can lead to account takeover if a user clicks the poisoned link. Version 2025-01a contains a patch. As a workaround, deactivate the password reset functionality by clearing `Notification email sender` and `Notification email subject` under System -> Configuration -> Options -> Password Settings.

    Published: 12 Feb 2025
    5.3
    Medium

    CVE-2024-6097

    Last Modified: 24 Feb 2025

    In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.

    Published: 12 Feb 2025