Latest CVE Feed
-
6.0
MEDIUMCVE-2024-45672
IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service.... Read more
Affected Products : security_verify_bridge- Published: Jan. 23, 2025
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2023-44441
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in tha... Read more
Affected Products : gimp- Published: May. 03, 2024
- Modified: Aug. 14, 2025
-
9.0
HIGHCVE-2025-8810
A vulnerability classified as critical was found in Tenda AC20 16.03.08.05. Affected by this vulnerability is the function strcpy of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. The att... Read more
- Published: Aug. 10, 2025
- Modified: Aug. 14, 2025
-
8.6
HIGHCVE-2025-8747
A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive.... Read more
Affected Products : keras- Published: Aug. 11, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-51823
libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parameter. The function uses strcpy to copy the interface name into a structure member (ctx->name) without validating the input length.... Read more
- Published: Aug. 11, 2025
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2016-8596
Buffer overflow in the csp_can_process_frame in csp_if_can.c in the libcsp library v1.4 and earlier allows hostile components connected to the canbus to execute arbitrary code via a long csp packet.... Read more
- EPSS Score: %3.36
- Published: Oct. 28, 2016
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2016-8597
Buffer overflow in the csp_sfp_recv_fp in csp_sfp.c in the libcsp library v1.4 and earlier allows hostile components with network access to the SFP underlying network layers to execute arbitrary code via specially crafted SFP packets.... Read more
- EPSS Score: %3.36
- Published: Oct. 28, 2016
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2016-8598
Buffer overflow in the zmq interface in csp_if_zmqhub.c in the libcsp library v1.4 and earlier allows hostile computers connected via a zmq interface to execute arbitrary code via a long packet.... Read more
- EPSS Score: %3.36
- Published: Oct. 28, 2016
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-51824
libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.... Read more
- Published: Aug. 11, 2025
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2023-44442
GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in tha... Read more
Affected Products : gimp- Published: May. 03, 2024
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-8355
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).... Read more
Affected Products : freeflow_core- Published: Aug. 08, 2025
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2023-44443
GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the targ... Read more
Affected Products : gimp- Published: May. 03, 2024
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-55346
User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the host, by sending a simple POST request.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.0
HIGHCVE-2025-45768
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for optin... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2024-8176
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhaust... Read more
- Published: Mar. 14, 2025
- Modified: Aug. 14, 2025
-
5.4
MEDIUMCVE-2022-29362
A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ParentID parameter.... Read more
- EPSS Score: %0.18
- Published: May. 25, 2022
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2023-44444
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target mus... Read more
Affected Products : gimp- Published: May. 03, 2024
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-52239
An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.... Read more
Affected Products : zkeacms- Published: Aug. 04, 2025
- Modified: Aug. 14, 2025
-
3.9
LOWCVE-2025-44964
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information.... Read more
Affected Products : bluestacks- Published: Aug. 05, 2025
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-50706
An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function... Read more
Affected Products : thinkphp- Published: Aug. 05, 2025
- Modified: Aug. 14, 2025