Latest CVE Feed
-
5.2
MEDIUMCVE-2025-23379
Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with adjacent network access could potentially ex... Read more
Affected Products : storage_manager- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-2657
A vulnerability classified as critical was found in projectworlds Apartment Visitors Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /front.php. The manipulation of the argument rid leads to sql injection. The... Read more
Affected Products : apartment_visitors_management_system- Published: Mar. 23, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-22479
Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit ... Read more
Affected Products : storage_manager- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-22478
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leadi... Read more
Affected Products : storage_manager- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: XML External Entity
-
8.8
HIGHCVE-2025-22477
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges.... Read more
Affected Products : storage_manager- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-26599
An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window t... Read more
Affected Products : enterprise_linux x_server grub2 libssh tigervnc international_components_for_unicode xwayland- Published: Feb. 25, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-26598
An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return th... Read more
Affected Products : enterprise_linux x_server grub2 libssh tigervnc international_components_for_unicode xwayland- Published: Feb. 25, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-26597
A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups,... Read more
Affected Products : enterprise_linux x_server grub2 libssh tigervnc international_components_for_unicode xwayland- Published: Feb. 25, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-26596
A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.... Read more
Affected Products : enterprise_linux x_server grub2 libssh tigervnc international_components_for_unicode xwayland- Published: Feb. 25, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-26595
A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy... Read more
Affected Products : enterprise_linux x_server grub2 libssh tigervnc international_components_for_unicode xwayland- Published: Feb. 25, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-26594
A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.... Read more
Affected Products : enterprise_linux x_server grub2 libssh tigervnc international_components_for_unicode xwayland- Published: Feb. 25, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-0690
The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, with a line big enoug... Read more
- Published: Feb. 24, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
6.4
MEDIUMCVE-2025-0677
A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size has overflown. When this occurs, ... Read more
- Published: Feb. 19, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
6.4
MEDIUMCVE-2025-0622
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was unloaded, leading... Read more
- Published: Feb. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
4.4
MEDIUMCVE-2024-45783
A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERRNO value. This issue may lead to a NULL pointer access.... Read more
- Published: Feb. 18, 2025
- Modified: May. 13, 2025
-
6.7
MEDIUMCVE-2024-45781
A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap out-of-bounds write, causing data integrity issues and eventually ... Read more
- Published: Feb. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
6.7
MEDIUMCVE-2024-45776
When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound reads and writes. This fl... Read more
- Published: Feb. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
5.2
MEDIUMCVE-2024-45775
A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check in case the memory allocation fails. Once the allocation fails, a NULL point will... Read more
- Published: Feb. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
6.7
MEDIUMCVE-2024-45774
A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The possibility of overwriting sensitive information to bypass secure... Read more
- Published: Feb. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2023-45892
An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.... Read more
Affected Products : insight- EPSS Score: %1.01
- Published: Jan. 02, 2024
- Modified: May. 13, 2025