Latest CVE Feed
-
7.5
HIGHCVE-2022-3725
Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file... Read more
- EPSS Score: %0.06
- Published: Oct. 27, 2022
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2022-25849
The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.... Read more
Affected Products : hyperdown- EPSS Score: %0.11
- Published: Oct. 26, 2022
- Modified: May. 09, 2025
-
7.5
HIGHCVE-2021-28831
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.... Read more
- EPSS Score: %0.88
- Published: Mar. 19, 2021
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2021-26937
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.... Read more
- EPSS Score: %2.98
- Published: Feb. 09, 2021
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2020-8165
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.... Read more
- EPSS Score: %90.96
- Published: Jun. 19, 2020
- Modified: May. 09, 2025
-
10.0
HIGHCVE-2015-0240
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute ar... Read more
- EPSS Score: %92.17
- Published: Feb. 24, 2015
- Modified: May. 09, 2025
-
7.0
HIGHCVE-2025-46327
gosnowflake is the Snowflake Golang driver. Versions starting from 1.7.0 to before 1.13.3, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS, the Driver reads logging configura... Read more
Affected Products : gosnowflake- Published: Apr. 28, 2025
- Modified: May. 09, 2025
- Vuln Type: Race Condition
-
7.0
HIGHCVE-2025-46328
snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS the Driver reads l... Read more
Affected Products : snowflake_connector- Published: Apr. 28, 2025
- Modified: May. 09, 2025
- Vuln Type: Race Condition
-
3.3
LOWCVE-2025-46329
libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging level was set to DEBUG, the Connector would log locally the client-side encry... Read more
Affected Products : connector_for_c\/c\+\+- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Information Disclosure
-
3.3
LOWCVE-2025-46330
libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code 400, as able to be retried. This could hang the application until SF_CON_... Read more
Affected Products : connector_for_c\/c\+\+- Published: Apr. 29, 2025
- Modified: May. 09, 2025
-
6.9
MEDIUMCVE-2025-46338
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to perform a reflected cross-site scripting (XSS) attack by submitting malicio... Read more
Affected Products : audiobookshelf- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46343
n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary files, which are accessible to authenticated users. Howe... Read more
Affected Products : n8n- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2024-58099
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame Andrew and Nikolay reported connectivity issues with Cilium's service load-balancing in case of vmxnet3. If a BPF program for n... Read more
Affected Products : linux_kernel- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-4060
A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. This issue affects some unknown processing of the file /category.php. The manipulation of the argument catname leads to sql injection. The attack may ... Read more
- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-4061
A vulnerability, which was classified as critical, was found in code-projects Clothing Store Management System up to 1.0. Affected is the function add_item. The manipulation of the argument st.productname leads to stack-based buffer overflow. Attacking lo... Read more
Affected Products : clothing_store_management_system- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-4062
A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by this vulnerability is the function cancel. The manipulation of the argument cancelcustomername leads to stack-based buffer overflow. It... Read more
Affected Products : theater_seat_booking_system- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-4063
A vulnerability was found in code-projects Student Information Management System 1.0 and classified as critical. Affected by this issue is the function cancel. The manipulation of the argument first_name/last_name leads to stack-based buffer overflow. The... Read more
Affected Products : student_information_management_system- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Memory Corruption
-
6.9
MEDIUMCVE-2025-4064
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation leads to improper access controls. It is possible to initiate the... Read more
Affected Products : online_traveling_system- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2025-4082
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of Thunderbird are una... Read more
- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2025-4083
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulner... Read more
- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Misconfiguration