Latest CVE Feed
-
5.6
MEDIUMCVE-2018-9056
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (... Read more
Affected Products : core_i3 core_i5 core_i7 xeon_e3 xeon_e3_1220_v5 xeon_e3_1225_v5 xeon_e3_1230_v5 xeon_e3_1235l_v5 xeon_e3_1240_v5 xeon_e3_1240l_v5 +199 more products- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2025-50986
diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its administrative settings interface. Various configuration fields such as ES_HOST, ES_INDEXREFRESH, ES_PORT, ES_SCROLLSIZE, ES_TRANSLOGSIZE,... Read more
Affected Products : diskover- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2025-50985
diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, q (query), and doctype are directly echoed into the HTML r... Read more
Affected Products : diskover- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2025-40929
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact... Read more
Affected Products :- Published: Sep. 08, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Denial of Service
-
5.6
MEDIUMCVE-2022-2366
Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations in place or use manipulated IPs for audit logging via manipulating the request headers.... Read more
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2025-5745
The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc6... Read more
Affected Products : glibc- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-5702
The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64... Read more
Affected Products : glibc- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-53489
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GoogleDocs4MW Extension:... Read more
Affected Products :- Published: Jul. 03, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2025-52993
A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.... Read more
Affected Products : nix- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Race Condition
-
5.6
MEDIUMCVE-2025-48172
CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.... Read more
Affected Products : chmlib- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-48061
wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logged in again afte... Read more
Affected Products : wire-webapp- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
5.6
MEDIUMCVE-2025-47806
In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash.... Read more
Affected Products : gstreamer- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-47182
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.... Read more
Affected Products : edge_chromium- Published: Jul. 11, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authorization
-
5.6
MEDIUMCVE-2025-46406
A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Division to perform limited privileged activities across the Division boundary. This issue affects Command Centre S... Read more
Affected Products :- Published: Jul. 10, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authorization
-
5.6
MEDIUMCVE-2025-42979
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any at... Read more
Affected Products : gui_for_windows- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cryptography
-
5.6
MEDIUMCVE-2025-2572
In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.... Read more
Affected Products : whatsup_gold- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authentication
-
5.6
MEDIUMCVE-2025-27636
Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to versio... Read more
Affected Products : camel- Published: Mar. 09, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
5.6
MEDIUMCVE-2025-26398
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed... Read more
Affected Products : database_performance_analyzer- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cryptography
-
5.6
MEDIUMCVE-2025-25683
AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects AlekSIS-Core 3.0, 3.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.2.0 and 3.2.1.... Read more
Affected Products :- Published: Mar. 12, 2025
- Modified: Mar. 12, 2025
- Vuln Type: Authorization
-
5.6
MEDIUMCVE-2025-25566
Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAlloc function. NOTE: the Supplier disputes this because the behavior is limited to a single allocation of a few hundred bytes with a com... Read more
Affected Products : vpn- Published: Mar. 12, 2025
- Modified: Jul. 19, 2025
- Vuln Type: Denial of Service