Latest CVE Feed
-
5.5
MEDIUMCVE-2025-54202
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_modeler- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.5
MEDIUMCVE-2025-54203
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_modeler- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.5
MEDIUMCVE-2025-54204
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_modeler- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.5
MEDIUMCVE-2025-54235
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_modeler- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.5
MEDIUMCVE-2025-54197
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_modeler- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.8
HIGHCVE-2025-54212
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a ... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.8
HIGHCVE-2025-54213
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.5
MEDIUMCVE-2025-54214
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.8
HIGHCVE-2025-54224
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.8
HIGHCVE-2025-54225
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.8
HIGHCVE-2025-54226
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
8.8
HIGHCVE-2025-54785
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to pe... Read more
Affected Products : suitecrm- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
-
5.5
MEDIUMCVE-2025-54227
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.5
MEDIUMCVE-2025-54228
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.5
MEDIUMCVE-2025-54198
Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_modeler- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.3
MEDIUMCVE-2025-6004
Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.... Read more
Affected Products : vault- Published: Aug. 01, 2025
- Modified: Aug. 13, 2025
-
3.7
LOWCVE-2025-6011
A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vault’s Userpass auth method. Fixed in Vault Com... Read more
Affected Products : vault- Published: Aug. 01, 2025
- Modified: Aug. 13, 2025
-
6.5
MEDIUMCVE-2025-6014
Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.... Read more
Affected Products : vault- Published: Aug. 01, 2025
- Modified: Aug. 13, 2025
-
5.7
MEDIUMCVE-2025-6015
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.... Read more
Affected Products : vault- Published: Aug. 01, 2025
- Modified: Aug. 13, 2025
-
6.8
MEDIUMCVE-2025-6037
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In t... Read more
Affected Products : vault- Published: Aug. 01, 2025
- Modified: Aug. 13, 2025