Latest CVE Feed
-
5.5
MEDIUMCVE-2025-24091
An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.... Read more
- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-30389
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_ai_bot_service- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-30390
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.... Read more
- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-30391
Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.... Read more
Affected Products : dynamics_365_customer_service- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-30392
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_ai_bot_service- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-33074
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.... Read more
Affected Products : azure_functions- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-44192
SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance.... Read more
Affected Products : simple_barangay_management_system- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-32127
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Markus Seyer Find Duplicates.This issue affects Find Duplicates: from n/a through 1.4.6. ... Read more
Affected Products : find_duplicates- Published: Apr. 15, 2024
- Modified: May. 12, 2025
-
7.6
HIGHCVE-2025-44193
SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint.... Read more
Affected Products : simple_barangay_management_system- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-2583
The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back to users, making it possible for users with the contributor role to conduct Stored XSS atta... Read more
Affected Products : shortcodes_ultimate- Published: Apr. 13, 2024
- Modified: May. 12, 2025
-
7.3
HIGHCVE-2025-44194
SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_household.... Read more
Affected Products : simple_barangay_management_system- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-24132
The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126, CarPlay Communication Plug-in R18.1. An attacker on the local network may cause an unexpected app termination.... Read more
- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-30422
A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126, CarPlay Communication Plug-in R18.1. An attacker on the local network may cause an unexpected app termination.... Read more
- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4140
A vulnerability, which was classified as critical, has been found in Netgear EX6120 1.0.3.94. Affected by this issue is the function sub_30394. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor... Read more
- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4141
A vulnerability, which was classified as critical, was found in Netgear EX6200 1.0.3.94. This affects the function sub_3C03C. The manipulation of the argument host leads to buffer overflow. It is possible to initiate the attack remotely. The vendor was co... Read more
- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4142
A vulnerability has been found in Netgear EX6200 1.0.3.94 and classified as critical. This vulnerability affects the function sub_3C8EC. The manipulation of the argument host leads to buffer overflow. The attack can be initiated remotely. The vendor was c... Read more
- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-4143
The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client registration. Fixed i... Read more
Affected Products : workers-oauth-provider- Published: May. 01, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4144
PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: https://gith... Read more
Affected Products : workers-oauth-provider- Published: May. 01, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4145
A vulnerability, which was classified as critical, has been found in Netgear EX6200 1.0.3.94. This issue affects the function sub_3D0BC. The manipulation of the argument host leads to buffer overflow. The attack may be initiated remotely. The vendor was c... Read more
- Published: May. 01, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4146
A vulnerability, which was classified as critical, was found in Netgear EX6200 1.0.3.94. Affected is the function sub_41940. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. The vendor was conta... Read more
- Published: May. 01, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption