CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-21135

    Last Modified: 12 Feb 2025

    Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-48858

    Last Modified: 1 Dec 2025

    Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-48857

    Last Modified: 21 Jan 2025

    NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21134

    Last Modified: 26 Feb 2026

    Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21133

    Last Modified: 26 Feb 2026

    Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2025
    9.8
    Critical

    CVE-2024-48856

    Last Modified: 21 Jan 2025

    Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.

    Published: 14 Jan 2025
    9
    Critical

    CVE-2024-49375

    Last Modified: 15 Apr 2026

    Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are: 1. The HTTP API must be enabled on the Rasa instance eg with `--enable-api`. This is not the default configuration. 2. For unauthenticated RCE to be exploitable, the user must not have configured any authentication or other security controls recommended in our documentation. 3. For authenticated RCE, the attacker must posses a valid authentication token or JWT to interact with the Rasa API. This issue has been addressed in rasa version 3.6.21 and all users are advised to upgrade. Users unable to upgrade should ensure that they require authentication and that only trusted users are given access.

    Published: 14 Jan 2025
    5.3
    Medium

    CVE-2024-48855

    Last Modified: 12 Feb 2025

    Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21129

    Last Modified: 12 Feb 2025

    Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21132

    Last Modified: 12 Feb 2025

    Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21130

    Last Modified: 12 Feb 2025

    Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21131

    Last Modified: 12 Feb 2025

    Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21128

    Last Modified: 12 Feb 2025

    Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2025
    2.4
    Low

    CVE-2025-23074

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfile Extension allows Functionality Misuse.This issue affects Mediawiki - SocialProfile Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.

    Published: 14 Jan 2025
    5.8
    Medium

    CVE-2025-23041

    Last Modified: 19 Sept 2025

    Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 14 Jan 2025
    5.3
    Medium

    CVE-2024-48854

    Last Modified: 21 Jan 2025

    Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21122

    Last Modified: 26 Feb 2026

    Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21127

    Last Modified: 26 Feb 2026

    Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrary code when the application loads. Exploitation of this issue requires user interaction in that a victim must run the vulnerable application.

    Published: 14 Jan 2025
    7.7
    High

    CVE-2025-0474

    Last Modified: 15 Apr 2026

    Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.

    Published: 14 Jan 2025
    8.7
    High

    CVE-2025-23042

    Last Modified: 26 Aug 2025

    Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the letter case of a blocked file or directory path. This vulnerability arises due to the lack of case normalization in the file path validation logic. On case-insensitive file systems, such as those used by Windows and macOS, this flaw enables attackers to circumvent security restrictions and access sensitive files that should be protected. This issue can lead to unauthorized data access, exposing sensitive information and undermining the integrity of Gradio's security model. Given Gradio's popularity for building web applications, particularly in machine learning and AI, this vulnerability may pose a substantial threat if exploited in production environments. This issue has been addressed in release version 5.6.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Jan 2025
    3.5
    Low

    CVE-2025-23073

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data. This issue briefly impacted the master branch of MediaWiki’s GlobalBlocking Extension.

    Published: 14 Jan 2025
    2.1
    Low

    CVE-2024-50349

    Last Modified: 18 Dec 2025

    Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using any credential helper), it prints out the host name for which the user is expected to provide a username and/or a password. At this stage, any URL-encoded parts have been decoded already, and are printed verbatim. This allows attackers to craft URLs that contain ANSI escape sequences that the terminal interpret to confuse users e.g. into providing passwords for trusted Git hosting sites when in fact they are then sent to untrusted sites that are under the attacker's control. This issue has been patch via commits `7725b81` and `c903985` which are included in release versions v2.48.1, v2.47.2, v2.46.3, v2.45.3, v2.44.3, v2.43.6, v2.42.4, v2.41.3, and v2.40.4. Users are advised to upgrade. Users unable to upgrade should avoid cloning from untrusted URLs, especially recursive clones.

    Published: 14 Jan 2025
    2.1
    Low

    CVE-2024-52006

    Last Modified: 18 Dec 2025

    Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. Git defines a line-based protocol that is used to exchange information between Git and Git credential helpers. Some ecosystems (most notably, .NET and node.js) interpret single Carriage Return characters as newlines, which renders the protections against CVE-2020-5260 incomplete for credential helpers that treat Carriage Returns in this way. This issue has been addressed in commit `b01b9b8` which is included in release versions v2.48.1, v2.47.2, v2.46.3, v2.45.3, v2.44.3, v2.43.6, v2.42.4, v2.41.3, and v2.40.4. Users are advised to upgrade. Users unable to upgrade should avoid cloning from untrusted URLs, especially recursive clones.

    Published: 14 Jan 2025
    5.4
    Medium

    CVE-2025-23072

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RefreshSpecial Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - RefreshSpecial Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.

    Published: 14 Jan 2025
    7.4
    High

    CVE-2024-50338

    Last Modified: 15 Apr 2026

    Git Credential Manager (GCM) is a secure Git credential helper built on .NET that runs on Windows, macOS, and Linux. The Git credential protocol is text-based over standard input/output, and consists of a series of lines of key-value pairs in the format `key=value`. Git's documentation restricts the use of the NUL (`\0`) character and newlines to form part of the keys or values. When Git reads from standard input, it considers both LF and CRLF as newline characters for the credential protocol by virtue of calling `strbuf_getline` that calls to `strbuf_getdelim_strip_crlf`. Git also validates that a newline is not present in the value by checking for the presence of the line-feed character (LF, `\n`), and errors if this is the case. This captures both LF and CRLF-type newlines. Git Credential Manager uses the .NET standard library `StreamReader` class to read the standard input stream line-by-line and parse the `key=value` credential protocol format. The implementation of the `ReadLineAsync` method considers LF, CRLF, and CR as valid line endings. This is means that .NET considers a single CR as a valid newline character, whereas Git does not. This mismatch of newline treatment between Git and GCM means that an attacker can craft a malicious remote URL. When a user clones or otherwise interacts with a malicious repository that requires authentication, the attacker can capture credentials for another Git remote. The attack is also heightened when cloning from repositories with submodules when using the `--recursive` clone option as the user is not able to inspect the submodule remote URLs beforehand. This issue has been patched in version 2.6.1 and all users are advised to upgrade. Users unable to upgrade should only interact with trusted remote repositories, and not clone with `--recursive` to allow inspection of any submodule URLs before cloning those submodules.

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-21245

    Last Modified: 13 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-21409

    Last Modified: 13 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-21223

    Last Modified: 13 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-21238

    Last Modified: 13 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-21240

    Last Modified: 13 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-21250

    Last Modified: 13 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-21417

    Last Modified: 13 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-21246

    Last Modified: 13 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21334

    Last Modified: 26 Feb 2026

    Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21333

    Last Modified: 26 Feb 2026

    Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

    Published: 14 Jan 2025
    9.8
    Critical

    CVE-2025-21311

    Last Modified: 13 Feb 2026

    Windows NTLM V1 Elevation of Privilege Vulnerability

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21326

    Last Modified: 13 Feb 2026

    Internet Explorer Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    4.3
    Medium

    CVE-2025-21332

    Last Modified: 13 Feb 2026

    MapUrlToZone Security Feature Bypass Vulnerability

    Published: 14 Jan 2025
    6.5
    Medium

    CVE-2025-21313

    Last Modified: 13 Feb 2026

    Windows Security Account Manager (SAM) Denial of Service Vulnerability

    Published: 14 Jan 2025
    7.5
    High

    CVE-2025-21218

    Last Modified: 13 Feb 2026

    Windows Kerberos Denial of Service Vulnerability

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21402

    Last Modified: 19 May 2026

    Microsoft Office OneNote Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21378

    Last Modified: 13 Feb 2026

    Windows CSC Service Elevation of Privilege Vulnerability

    Published: 14 Jan 2025
    5.5
    Medium

    CVE-2025-21374

    Last Modified: 13 Feb 2026

    Windows CSC Service Information Disclosure Vulnerability

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21372

    Last Modified: 26 Feb 2026

    Microsoft Brokering File System Elevation of Privilege Vulnerability

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21370

    Last Modified: 13 Feb 2026

    Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21361

    Last Modified: 19 May 2026

    Microsoft Outlook Remote Code Execution Vulnerability

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-21360

    Last Modified: 13 Feb 2026

    Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

    Published: 14 Jan 2025
    7.5
    High

    CVE-2025-21343

    Last Modified: 13 Feb 2026

    Windows Web Threat Defense User Service Information Disclosure Vulnerability

    Published: 14 Jan 2025
    5.5
    Medium

    CVE-2025-21340

    Last Modified: 13 Feb 2026

    Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-21339

    Last Modified: 13 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 14 Jan 2025