Latest CVE Feed
-
7.8
HIGHCVE-2022-41201
Due to lack of proper memory management, when a victim opens a manipulated Right Hemisphere Binary (.rh, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be trigge... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Oct. 11, 2022
- Modified: Jun. 05, 2025
-
5.3
MEDIUMCVE-2020-8929
A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker to change the ID part of a ciphertext, which result in the creation of a second ciphertext that can decrypt to the same plaintext. Thi... Read more
- Published: Oct. 19, 2020
- Modified: Jun. 05, 2025
-
6.4
MEDIUMCVE-2024-6155
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in all versions up to, and including, 9.0.0 due to a missing capability check ... Read more
Affected Products : greenshift_-_animation_and_page_builder_blocks- Published: Jan. 09, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2024-4420
There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3. * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input that is not an encoded JSON object, but still a valid enco... Read more
- Published: May. 21, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2025-37800
In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference in dev_uevent() If userspace reads "uevent" device attribute at the same time as another threads unbinds the device from its driver, ... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-37801
In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Add check for the return value of spi_imx_setupxfer(). spi_imx->rx and spi_imx->tx function pointer can be NULL when spi_imx_setupxfer() ... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-37802
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING" wait_event_timeout() will set the state of the current task to TASK_UNINTERRUPTIBLE, before doing the condition check. T... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-37803
In the Linux kernel, the following vulnerability has been resolved: udmabuf: fix a buf size overflow issue during udmabuf creation by casting size_limit_mb to u64 when calculate pglimit.... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-37805
In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitialized work_structs Betty reported hitting the following warning: [ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-1329
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyaddr function.... Read more
- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-35817
DevExpress before 23.1.3 allows AsyncDownloader SSRF.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
5.3
MEDIUMCVE-2023-35816
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-11642
The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the '... Read more
Affected Products : post_grid_master- Published: Jan. 09, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2023-35815
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-35814
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-1330
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyname function.... Read more
- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-1331
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.... Read more
- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
10.0
CRITICALCVE-2025-29813
[Spoofable identity claims] Authentication Bypass by Assumed-Immutable Data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_devops- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2024-11725
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the updateWcWarrantySettings() function in all versions up t... Read more
Affected Products : sms_alert_order_notifications- Published: Jan. 07, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-29827
Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_automation- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization