Latest CVE Feed
-
5.5
MEDIUMCVE-2025-2954
A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of the component File Handler. The manipulation leads to improper access contro... Read more
Affected Products : openmanus- Published: Mar. 30, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-2953
A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit h... Read more
Affected Products : pytorch- Published: Mar. 30, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-2924
A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl_deserialize of the file src/H5HLcache.c. The manipulation of the argument free_block leads to heap-based buffer overflow. It is possib... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-2915
A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__accum_free of the file src/H5Faccum.c. The manipulation of the argument overlap_size leads to heap-based buffer overflow. Attacking loca... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-2591
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwid... Read more
Affected Products : assimp- Published: Mar. 21, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-2744
A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component Material Upload Interface. The manipulation of the arg... Read more
- Published: Mar. 25, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-2510
The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authen... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-2300
Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00.... Read more
Affected Products : ops_center_common_services- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-29808
Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2022- Published: Apr. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Cryptography
-
5.5
MEDIUMCVE-2025-29477
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.... Read more
Affected Products : fluent_bit- Published: Apr. 04, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-29478
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.... Read more
Affected Products : fluent_bit- Published: Apr. 07, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2023-30648
Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.... Read more
- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-27742
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Apr. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-27736
Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows windows_11_23h2 +4 more products- Published: Apr. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-27562
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.... Read more
Affected Products : openharmony- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2023-30924
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-27537
Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-25325
An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link.... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-27536
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.... Read more
Affected Products : openharmony- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-27202
Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issu... Read more
- Published: Apr. 08, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Information Disclosure