Latest CVE Feed
-
5.6
MEDIUMCVE-2025-20077
Missing release of memory after effective lifetime in the UEFI OobRasMmbiHandlerDriver module for some Intel(R) reference server platforms may allow a privileged user to enable denial of service via local access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
6.7
MEDIUMCVE-2025-22838
Uncontrolled search path for some Intel(R) RealSense(TM) Dynamic Calibrator software before version 2.14.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
4.4
MEDIUMCVE-2025-20025
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.2
HIGHCVE-2025-20037
Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
2.6
LOWCVE-2025-27707
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
6.9
MEDIUMCVE-2025-24921
Improper neutralization for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable information disclosure via adjacent access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
6.7
MEDIUMCVE-2025-26404
Uncontrolled search path for some Intel(R) DSA software before version 25.2.15.9 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : driver_\&_support_assistant- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
6.7
MEDIUMCVE-2025-24302
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.4
HIGHCVE-2025-22840
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Xeon(R) 6 Scalable processors may allow an authenticated user to potentially enable escalation of privilege via local access... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
6.5
MEDIUMCVE-2025-8310
Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
4.9
MEDIUMCVE-2025-5466
XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker ... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.5
HIGHCVE-2025-5462
A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remot... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.5
MEDIUMCVE-2025-5468
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025)... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
6.3
MEDIUMCVE-2024-38805
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.... Read more
Affected Products : edk2- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
7.5
HIGHCVE-2025-5456
A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a re... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
3.3
LOWCVE-2025-24511
Improper initialization in the Linux kernel-mode driver for some Intel(R) I350 Series Ethernet before version 5.19.2 may allow an authenticated user to potentially enable Information disclosure via data exposure.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.1
MEDIUMCVE-2025-55166
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method only searches for lower-case attribute name, which allows to by-pass the isHrefSafeValue check. As a result this allows cross-site scr... Read more
Affected Products : svg-sanitizer- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.3
MEDIUMCVE-2025-25007
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
8.1
HIGHCVE-2025-3831
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
5.3
MEDIUMCVE-2025-25006
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025