CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2025-25343

    Last Modified: 5 Mar 2025

    Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.

    Published: 12 Feb 2025
    9.8
    Critical

    CVE-2025-25349

    Last Modified: 5 Mar 2025

    PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.

    Published: 12 Feb 2025
    5.6
    Medium

    CVE-2020-3432

    Last Modified: 24 Jun 2025

    A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a symbolic link (symlink) to a target file on a specific path. A successful exploit could allow the attacker to corrupt the contents of the file. If the file is a critical systems file, the exploit could lead to a denial of service condition. To exploit this vulnerability, the attacker would need to have valid credentials on the system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

    Published: 11 Feb 2025
    7.5
    High

    CVE-2023-31345

    Last Modified: 15 Apr 2026

    Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.

    Published: 11 Feb 2025
    7.5
    High

    CVE-2024-0112

    Last Modified: 15 Apr 2026

    NVIDIA Jetson AGX Orin™ and NVIDIA IGX Orin software contain a vulnerability where an attacker can cause an improper input validation issue by escalating certain permissions to a limited degree. A successful exploit of this vulnerability might lead to code execution, denial of service, data corruption, information disclosure, or escalation of privilege.

    Published: 11 Feb 2025
    5
    Medium

    CVE-2023-20508

    Last Modified: 15 Apr 2026

    Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, potentially leading to loss of confidentiality, integrity, or availability.

    Published: 11 Feb 2025
    8.1
    High

    CVE-2025-25203

    Last Modified: 15 Apr 2026

    CtrlPanel is open-source billing software for hosting providers. Prior to version 1.0, a Cross-Site Scripting (XSS) vulnerability exists in the `TicketsController` and `Moderation/TicketsController` due to insufficient input validation on the `priority` field during ticket creation and unsafe rendering of this field in the moderator panel. Version 1.0 contains a patch for the issue.

    Published: 11 Feb 2025
    6
    Medium

    CVE-2023-31352

    Last Modified: 15 Apr 2026

    A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private data.

    Published: 11 Feb 2025
    7.5
    High

    CVE-2023-31343

    Last Modified: 15 Apr 2026

    Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.

    Published: 11 Feb 2025
    7.5
    High

    CVE-2023-31342

    Last Modified: 15 Apr 2026

    Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-1240

    Last Modified: 18 Aug 2025

    WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 7Z files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24986.

    Published: 11 Feb 2025
    0
    Low

    CVE-2024-32037

    Last Modified: 17 Apr 2026

    GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the search end-point response headers contain information about Elasticsearch software in use. This information is valuable from a security point of view because it allows software used by the server to be easily identified. GeoNetwork 4.4.5 and 4.2.10 fix this issue. No known workarounds are available.

    Published: 11 Feb 2025
    3
    Low

    CVE-2023-31331

    Last Modified: 15 Apr 2026

    Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initializations, resulting in stack memory corruption that could potentially lead to loss of integrity or availability.

    Published: 11 Feb 2025
    9.8
    Critical

    CVE-2022-3180

    Last Modified: 5 Jun 2025

    The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.

    Published: 11 Feb 2025
    5.3
    Medium

    CVE-2023-20582

    Last Modified: 15 Apr 2026

    Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table entry (PTE) faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest memory integrity.

    Published: 11 Feb 2025
    2.5
    Low

    CVE-2023-20581

    Last Modified: 15 Apr 2026

    Improper access control in the IOMMU may allow a privileged attacker to bypass RMP checks, potentially leading to a loss of guest memory integrity.

    Published: 11 Feb 2025
    5.7
    Medium

    CVE-2023-20515

    Last Modified: 15 Apr 2026

    Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss of integrity, confidentiality, or availability.

    Published: 11 Feb 2025
    2.3
    Low

    CVE-2023-20507

    Last Modified: 15 Apr 2026

    An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data integrity.

    Published: 11 Feb 2025
    8.2
    High

    CVE-2024-21924

    Last Modified: 15 Apr 2026

    SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services handlers, potentially resulting in arbitrary code execution.

    Published: 11 Feb 2025
    7.3
    High

    CVE-2023-31361

    Last Modified: 15 Apr 2026

    A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

    Published: 11 Feb 2025
    7.3
    High

    CVE-2023-31360

    Last Modified: 15 Apr 2026

    Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0911

    Last Modified: 12 Feb 2025

    PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25957.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0910

    Last Modified: 12 Feb 2025

    PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25748.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0909

    Last Modified: 12 Feb 2025

    PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25678.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0908

    Last Modified: 12 Feb 2025

    PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25557.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0907

    Last Modified: 12 Feb 2025

    PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25435.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0906

    Last Modified: 12 Feb 2025

    PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25434.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0905

    Last Modified: 12 Feb 2025

    PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25433.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0904

    Last Modified: 12 Feb 2025

    PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25422.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0903

    Last Modified: 12 Feb 2025

    PDF-XChange Editor RTF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of RTF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25421.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0902

    Last Modified: 12 Feb 2025

    PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-25405.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0901

    Last Modified: 12 Feb 2025

    PDF-XChange Editor Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25372.

    Published: 11 Feb 2025
    7.3
    High

    CVE-2024-21966

    Last Modified: 15 Apr 2026

    A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 11 Feb 2025
    9.8
    Critical

    CVE-2025-1044

    Last Modified: 18 Feb 2025

    Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 443 by default. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25336.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-1052

    Last Modified: 18 Feb 2025

    Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mintty. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of sixel images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-23382.

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-0899

    Last Modified: 12 Feb 2025

    PDF-XChange Editor AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25349.

    Published: 11 Feb 2025
    6.3
    Medium

    CVE-2025-25202

    Last Modified: 27 Aug 2025

    Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link strategy _or_ are manually revoking tokens are affected by revoked tokens being allowed to verify as valid. Unless one hase implemented any kind of custom token revocation feature in your application, then one will not be affected. The impact here for users using builtin functionality is that magic link tokens are reusable until they expire. With that said, magic link tokens are only valid for 10 minutes, so the surface area for abuse is extremely low here. The flaw is patched in version 4.4.9. Additionally a compile time warning is shown to users with remediation instructions if they upgrade. 4.4.9 ships with an upgrader, so those who use `mix igniter.upgrade ash_authentication` will have the necessary patch applied. Otherwise, one may run the upgrader manually as described in the error message. As a workaround, delete the generated `:revoked?` generic action in the token resource. This will cause it to use the one internal to Ash Authentication which has always been correct. Alternatively, manually make the changes that are included in the patch.

    Published: 11 Feb 2025
    7.3
    High

    CVE-2025-24042

    Last Modified: 26 Feb 2026

    Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21373

    Last Modified: 13 Feb 2026

    Windows Installer Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7
    High

    CVE-2025-21414

    Last Modified: 13 Feb 2026

    Windows Core Messaging Elevation of Privileges Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21322

    Last Modified: 13 Feb 2026

    Microsoft PC Manager Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    6.5
    Medium

    CVE-2025-21254

    Last Modified: 13 Feb 2026

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

    Published: 11 Feb 2025
    6.5
    Medium

    CVE-2025-21216

    Last Modified: 13 Feb 2026

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

    Published: 11 Feb 2025
    6.5
    Medium

    CVE-2025-21212

    Last Modified: 13 Feb 2026

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

    Published: 11 Feb 2025
    7
    High

    CVE-2025-21184

    Last Modified: 13 Feb 2026

    Windows Core Messaging Elevation of Privileges Vulnerability

    Published: 11 Feb 2025
    7.5
    High

    CVE-2025-21181

    Last Modified: 13 Feb 2026

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

    Published: 11 Feb 2025
    4.8
    Medium

    CVE-2025-21179

    Last Modified: 13 Feb 2026

    DHCP Client Service Denial of Service Vulnerability

    Published: 11 Feb 2025
    8
    High

    CVE-2025-21400

    Last Modified: 13 Feb 2026

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21397

    Last Modified: 26 Feb 2026

    Microsoft Office Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21394

    Last Modified: 26 Feb 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 11 Feb 2025