Latest CVE Feed
-
5.5
MEDIUMCVE-2025-54191
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_painter- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-54192
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_painter- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-54227
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-54238
Dimension versions 4.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-55005
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB colorspaces, the logmap construction fails to handle cases where the reference-black or r... Read more
Affected Products : imagemagick- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-53241
Server-Side Request Forgery (SSRF) vulnerability in kodeshpa Simplified allows Server Side Request Forgery. This issue affects Simplified: from n/a through 1.0.9.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Server-Side Request Forgery
-
5.5
MEDIUMCVE-2025-55207
Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios prior to version 9.4.1. Astro 5.12.8 addressed CVE-2025-54793 where https://example.com//... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-1474
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue vio... Read more
Affected Products : mlflow- Published: Mar. 20, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-2557
A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is some unknown functionality of the component Command API. The manipulation leads to improper access controls. The attack needs to be done w... Read more
Affected Products :- Published: Mar. 20, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2024-8314
An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user sessi... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2024-41862
Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this is... Read more
Affected Products : substance_3d_sampler- Published: Aug. 14, 2024
- Modified: Aug. 14, 2024
-
5.5
MEDIUMCVE-2025-23285
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful exploit of this vulnerability might lead to denial of service.... Read more
Affected Products :- Published: Aug. 02, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-41658
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-8530
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file eladmin-system\src\main\resources\config\application-prod.yml of the component Druid. The ma... Read more
Affected Products : eladmin- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-54639
ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
5.5
MEDIUMCVE-2025-21019
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.... Read more
Affected Products : health- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-24844
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.... Read more
Affected Products : openharmony- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2019-19819
The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unicode content.... Read more
Affected Products : nitropdf- EPSS Score: %0.01
- Published: Jan. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-57784
An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a directory traversal.... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2018-9447
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is n... Read more
Affected Products : android- Published: Jan. 17, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Denial of Service