Latest CVE Feed
-
5.5
MEDIUMCVE-2022-42762
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.5
MEDIUMCVE-2022-42761
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.5
MEDIUMCVE-2022-42760
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.5
MEDIUMCVE-2022-42759
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
3.3
LOWCVE-2022-42758
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
3.3
LOWCVE-2022-42757
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.5
MEDIUMCVE-2022-42755
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-1304
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.... Read more
- Published: Apr. 14, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2022-0547
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially corre... Read more
- Published: Mar. 18, 2022
- Modified: Apr. 23, 2025
-
9.0
HIGHCVE-2021-44142
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit co... Read more
- Published: Feb. 21, 2022
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2023-25829
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.... Read more
Affected Products : portal_for_arcgis- Published: May. 09, 2023
- Modified: Apr. 23, 2025
-
10.0
CRITICALCVE-2025-26853
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.... Read more
- Published: Mar. 20, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-56736
Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.... Read more
Affected Products : hertzbeat- Published: Apr. 16, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-32414
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between by... Read more
Affected Products : libxml2- Published: Apr. 08, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-28101
An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request.... Read more
Affected Products : flaskblog- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authorization
-
10.0
CRITICALCVE-2025-26852
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.... Read more
- Published: Mar. 20, 2025
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2025-28009
A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.... Read more
Affected Products : dietiqa- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-29722
A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.... Read more
Affected Products : commercify- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-25192
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debug mode and access sensitive information. Version 10.0.18 contains a patch. As a workaround, one may delete the `install/update.php` fil... Read more
Affected Products : glpi- Published: Feb. 25, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Information Disclosure
-
8.6
HIGHCVE-2025-27501
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form of authentication. This endpoint accepts a user-supplied URL parameter to connect to an OpenZiti ... Read more
Affected Products : openziti- Published: Mar. 03, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Server-Side Request Forgery