Latest CVE Feed
-
9.8
CRITICALCVE-2025-8042
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.... Read more
Affected Products : firefox- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-8041
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141.... Read more
Affected Products : firefox- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-7777
The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or phishing campaigns.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-27239
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: Feb. 25, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2024-27245
Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: Feb. 25, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2024-27246
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: Feb. 25, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-40536
Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 were discovered to contain a stack overflow via the pin_3g_code parameter in the config_3g_para function.... Read more
- Published: Jul. 16, 2024
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2024-40535
Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the config_3g_para function.... Read more
- Published: Jul. 16, 2024
- Modified: Aug. 20, 2025
-
7.5
HIGHCVE-2024-27241
Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: Jul. 15, 2024
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2024-39181
Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid parameter in thegenerate_conf_router() function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POS... Read more
- Published: Jul. 09, 2024
- Modified: Aug. 20, 2025
-
5.3
MEDIUMCVE-2024-36402
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to th... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-36403
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded disk consumption, where an unauthenticated adversary can induce it to download and cache large amounts of re... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-52602
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. This is fi... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2024-52791
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to other servers as part of normal operation, and these resource owners can return large amounts of JSON back to MMR for parsing. In parsing,... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
6.8
MEDIUMCVE-2024-56515
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are disabled by default), a user may upload a file which claims to be either of these types and request a thumbn... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-43745
A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.1... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-33008
IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-44373
A Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php.... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Path Traversal
-
0.0
NACVE-2025-38615
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: cancle set bad inode after removing name fails The reproducer uses a file0 on a ntfs3 file system with a corrupted i_link. When renaming, the file0's inode is marked as a bad ... Read more
Affected Products : linux_kernel- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Race Condition
-
0.0
NACVE-2025-38582
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix double destruction of rsv_qp rsv_qp may be double destroyed in error flow, first in free_mr_init(), and then in hns_roce_exit(). Fix it by moving the free_mr_init() call i... Read more
Affected Products : linux_kernel- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Memory Corruption