Latest CVE Feed
-
9.8
CRITICALCVE-2024-11403
There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does... Read more
Affected Products : libjxl- Published: Nov. 25, 2024
- Modified: Jul. 24, 2025
-
5.5
MEDIUMCVE-2025-2926
A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. ... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-2925
A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MM_realloc of the file src/H5MM.c. The manipulation of the argument mem leads to double free. The attack needs to be approached lo... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-2924
A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl_deserialize of the file src/H5HLcache.c. The manipulation of the argument free_block leads to heap-based buffer overflow. It is possib... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-2923
A vulnerability, which was classified as problematic, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5F_addr_encode_len of the file src/H5Fint.c. The manipulation of the argument pp leads to heap-based buffer overflow. Attack... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-2915
A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__accum_free of the file src/H5Faccum.c. The manipulation of the argument overlap_size leads to heap-based buffer overflow. Attacking loca... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-2914
A vulnerability classified as problematic has been found in HDF5 up to 1.14.6. This affects the function H5FS__sinfo_Srialize_Sct_cb of the file src/H5FScache.c. The manipulation of the argument sect leads to heap-based buffer overflow. Local access is re... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-2913
A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5FL__blk_gc_list of the file src/H5FL.c. The manipulation of the argument H5FL_blk_head_t leads to use after free. An attack has to be a... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-2912
A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5O_msg_flush of the file src/H5Omessage.c. The manipulation of the argument oh leads to heap-based buffer overflow. The at... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-22115
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block group refcount race in btrfs_create_pending_block_groups() Block group creation is done in two phases, which results in a slightly unintuitive property: a block group c... Read more
Affected Products : linux_kernel- Published: Apr. 16, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Race Condition
-
7.7
HIGHCVE-2024-21548
Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects. **Note:** This issue relates to the wi... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Jul. 24, 2025
-
9.8
CRITICALCVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687.... Read more
Affected Products : linux_kernel aix infosphere_information_server windows infosphere_information_server_on_cloud- Published: Nov. 16, 2022
- Modified: Jul. 23, 2025
-
8.8
HIGHCVE-2022-3388
An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.... Read more
- Published: Nov. 21, 2022
- Modified: Jul. 23, 2025
-
4.4
MEDIUMCVE-2021-39077
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587.... Read more
- Published: Nov. 03, 2022
- Modified: Jul. 23, 2025
-
6.5
MEDIUMCVE-2024-40585
An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiAnalyzer version 7.4.0, version 7.2.... Read more
- Published: Mar. 14, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2023-33300
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communica... Read more
Affected Products : fortinac- Published: Mar. 14, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-7762
A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some unknown processing of the file /menu_nat_more.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer o... Read more
- Published: Jul. 17, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-7758
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected by this issue is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulat... Read more
- Published: Jul. 17, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Memory Corruption
-
8.1
HIGHCVE-2024-8238
In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against the str.format_map() method, allowing an attacker to leak server-side secrets... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-6851
In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFil... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Path Traversal