Latest CVE Feed
- 
                                
                                
7.8
HIGHCVE-2025-21053
Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.... Read more
Affected Products : android- Published: Oct. 10, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-21054
Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.... Read more
Affected Products : android- Published: Oct. 10, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.5
HIGHCVE-2025-21055
Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.... Read more
Affected Products : android- Published: Oct. 10, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
3.3
LOWCVE-2025-60361
radare2 v5.9.8 and before contains a memory leak in the function bochs_open.... Read more
Affected Products : radare2- Published: Oct. 17, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.3
MEDIUMCVE-2025-59438
Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.... Read more
Affected Products : mbed_tls- Published: Oct. 21, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-61181
daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.... Read more
Affected Products : daicuo- Published: Oct. 21, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-61194
daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.... Read more
Affected Products : daicuo- Published: Oct. 21, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-60360
radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.... Read more
Affected Products : radare2- Published: Oct. 17, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-60359
radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.... Read more
Affected Products : radare2- Published: Oct. 17, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-57164
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.... Read more
Affected Products : flowise- Published: Oct. 17, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.1
CRITICALCVE-2025-55100
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio10_sam_parse_func() when parsing a list of sampling frequencies.... Read more
Affected Products : threadx_usbx- Published: Oct. 17, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-55098
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_device_type_get() when parsing a descriptor of an USB audio device.... Read more
Affected Products : threadx_usbx- Published: Oct. 17, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-55099
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing a descriptor with attacker-controlled frequency fields.... Read more
Affected Products : threadx_usbx- Published: Oct. 17, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-55097
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_streaming_sampling_get() when parsing a descriptor of an USB streaming device.... Read more
Affected Products : threadx_usbx- Published: Oct. 17, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-55096
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_hid_report_descriptor_get() when parsing a descriptor of an USB HID device.... Read more
- Published: Oct. 17, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.5
HIGHCVE-2025-60358
radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.... Read more
Affected Products : radare2- Published: Oct. 16, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-62412
LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to inject HTML code. This vulnerability is fixed in 25.10.0.... Read more
Affected Products : librenms- Published: Oct. 16, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-62411
LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the... Read more
Affected Products : librenms- Published: Oct. 16, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-61255
Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search parameter, where unsanitized input allows arbitrary HTML and JavaScript injection, potentially resulting in information disclosure and us... Read more
Affected Products : bank_locker_management_system- Published: Oct. 21, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
5.3
MEDIUMCVE-2025-60134
Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Media Categories wp-media-categories allows Cross Site Request Forgery.This issue affects WP Media Categories: from n/a through <= 2.1.0.... Read more
Affected Products :- Published: Oct. 22, 2025
 - Modified: Oct. 22, 2025
 - Vuln Type: Cross-Site Request Forgery