Latest CVE Feed
- 
                                
                                
5.7
MEDIUMCVE-2025-37727
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex... Read more
- Published: Oct. 10, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
5.7
MEDIUMCVE-2025-59730
When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded with codec 48 can specify their resolution (width x height). A buffer of appropriate size is allocated depending on t... Read more
Affected Products : ffmpeg- Published: Oct. 06, 2025
 - Modified: Oct. 06, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.7
MEDIUMCVE-2025-60969
Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.... Read more
- Published: Oct. 06, 2025
 - Modified: Oct. 10, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
5.7
MEDIUMCVE-2025-11411
NLnet Labs Unbound up to and including version 1.24.0 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation informatio... Read more
Affected Products : unbound- Published: Oct. 22, 2025
 - Modified: Oct. 22, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
5.7
MEDIUMCVE-2025-21044
Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.... Read more
Affected Products : android- Published: Oct. 10, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.7
MEDIUMCVE-2025-9955
An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs and user-store configuration. A low-privileged user can access log dat... Read more
- Published: Oct. 16, 2025
 - Modified: Oct. 21, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
5.7
MEDIUMCVE-2025-2140
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.... Read more
- Published: Oct. 12, 2025
 - Modified: Oct. 16, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
5.6
MEDIUMCVE-2025-54271
Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check an... Read more
- Published: Oct. 15, 2025
 - Modified: Oct. 17, 2025
 - Vuln Type: Race Condition
 
 - 
                                
                                
5.6
MEDIUMCVE-2025-42701
A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Race Condition
 
 - 
                                
                                
5.6
MEDIUMCVE-2025-53860
A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems. Note: Software versions which have reached End of Technical Suppor... Read more
- Published: Oct. 15, 2025
 - Modified: Oct. 21, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
5.5
MEDIUMCVE-2024-42192
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.... Read more
Affected Products : traveler_for_microsoft_outlook- Published: Oct. 16, 2025
 - Modified: Oct. 29, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-58293
Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Oct. 11, 2025
 - Modified: Oct. 16, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-43313
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.7.7, macOS Sonoma 14.7.7, macOS Sequoia 15.6. An app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: Oct. 15, 2025
 - Modified: Oct. 16, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-36002
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files which can be read by a local user.... Read more
- Published: Oct. 16, 2025
 - Modified: Oct. 25, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-58290
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Oct. 11, 2025
 - Modified: Oct. 16, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-54269
Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this is... Read more
- Published: Oct. 15, 2025
 - Modified: Oct. 17, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-59253
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.... Read more
Affected Products : windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 +7 more products- Published: Oct. 14, 2025
 - Modified: Oct. 17, 2025
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-11414
A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally... Read more
Affected Products : binutils- Published: Oct. 07, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-59419
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r... Read more
Affected Products : netty- Published: Oct. 15, 2025
 - Modified: Oct. 17, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-11839
A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the ... Read more
Affected Products : binutils- Published: Oct. 16, 2025
 - Modified: Oct. 21, 2025
 - Vuln Type: Memory Corruption