Latest CVE Feed
-
8.8
HIGHCVE-2023-34306
Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required... Read more
Affected Products : graphite- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
8.8
HIGHCVE-2023-34307
Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to expl... Read more
Affected Products : graphite- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
8.8
HIGHCVE-2023-34308
Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to expl... Read more
Affected Products : graphite- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
6.5
MEDIUMCVE-2025-5981
Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images.... Read more
Affected Products : osv-scalibr- Published: Jun. 18, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2023-53159
The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.... Read more
- Published: Jul. 28, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2023-53157
The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UDP packet.... Read more
Affected Products : rosenpass- Published: Jul. 28, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-58266
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.... Read more
Affected Products : shlex- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
6.0
MEDIUMCVE-2025-7954
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.... Read more
Affected Products : shopware- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Race Condition
-
10.0
CRITICALCVE-2012-10026
The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-58265
The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.... Read more
Affected Products : snow- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2023-53156
The transpose crate before 0.2.3 for Rust allows an integer overflow via input_width and input_height arguments.... Read more
Affected Products : transpose- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2024-58263
The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.... Read more
Affected Products : cosmwasm-std- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
3.3
LOWCVE-2023-51568
Kofax Power PDF OXPS File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit this ... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
5.5
MEDIUMCVE-2023-51567
Kofax Power PDF OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit t... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
7.8
HIGHCVE-2023-51565
Kofax Power PDF XPS File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerabil... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
5.1
MEDIUMCVE-2024-58262
The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.... Read more
Affected Products : curve25519-dalek- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Cryptography
-
7.8
HIGHCVE-2023-37338
Kofax Power PDF GIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
7.8
HIGHCVE-2023-37339
Kofax Power PDF PCX File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
7.8
HIGHCVE-2023-37340
Kofax Power PDF PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
7.8
HIGHCVE-2023-37336
Kofax Power PDF TIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025