Latest CVE Feed
-
9.8
CRITICALCVE-2024-57590
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST ... Read more
- Published: Jan. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-22646
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemes aThemes Addons for Elementor allows Stored XSS.This issue affects aThemes Addons for Elementor: from n/a through 1.0.8.... Read more
Affected Products : athemes_addons_for_elementor- Published: Mar. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-32158
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aThemes aThemes Addons for Elementor. This issue affects aThemes Addons for Elementor: from n/a through 1.0.15.... Read more
Affected Products : athemes_addons_for_elementor- Published: Apr. 10, 2025
- Modified: May. 29, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-0993
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2025-1110
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-2853
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition.... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-3111
An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of servi... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Denial of Service
-
4.6
MEDIUMCVE-2025-0605
An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-0679
An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-44884
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44885
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44886
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44887
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44888
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44890
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44893
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44883
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-2998
A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this att... Read more
Affected Products : pytorch- Published: Mar. 31, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44891
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44894
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption