Latest CVE Feed
-
9.8
CRITICALCVE-2025-44896
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-3000
A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the p... Read more
Affected Products : pytorch- Published: Mar. 31, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-3001
A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the publi... Read more
Affected Products : pytorch- Published: Mar. 31, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44897
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44898
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-5064
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: May. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-5065
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: May. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-5066
Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Mediu... Read more
- Published: May. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-5067
Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: May. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-5280
Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: May. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-5281
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: May. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Information Disclosure
-
6.2
MEDIUMCVE-2025-29918
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an infinite loop when negated PCRE is used. Packet processing thread becomes stuck in infinite l... Read more
Affected Products : suricata- Published: Apr. 10, 2025
- Modified: May. 29, 2025
- Vuln Type: Denial of Service
-
6.2
MEDIUMCVE-2025-29917
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The bytes setting in the decode_base64 keyword is not properly limited. Due to this, signatures using the keyword and setting can cause l... Read more
Affected Products : suricata- Published: Apr. 10, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2025-29916
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the `hashsize` to use. This size setting isn't properly limited, so the hash table a... Read more
Affected Products : suricata- Published: Apr. 10, 2025
- Modified: May. 29, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-46672
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.... Read more
Affected Products : cryptolib- Published: Apr. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Cryptography
-
6.3
MEDIUMCVE-2025-3954
A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some unknown functionality of the component Referer Handler. The manipulation leads to server-side request forgery. The attack may be launc... Read more
Affected Products : churchcrm- Published: Apr. 26, 2025
- Modified: May. 29, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-29915
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The AF_PACKET defrag option is enabled by default and allows AF_PACKET to re-assemble fragmented packets before reaching Suricata. Howeve... Read more
Affected Products : suricata- Published: Apr. 10, 2025
- Modified: May. 29, 2025
- Vuln Type: Misconfiguration
-
6.2
MEDIUMCVE-2023-45913
Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using D... Read more
Affected Products : mesa- Published: Mar. 27, 2024
- Modified: May. 29, 2025
-
7.5
HIGHCVE-2023-45931
Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.... Read more
Affected Products : mesa- Published: Mar. 27, 2024
- Modified: May. 29, 2025
-
5.3
MEDIUMCVE-2023-45919
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.... Read more
Affected Products : mesa- Published: Mar. 27, 2024
- Modified: May. 29, 2025