Latest CVE Feed
-
5.4
MEDIUMCVE-2024-57186
In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.... Read more
Affected Products : erxes- Published: Jun. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Path Traversal
-
5.4
MEDIUMCVE-2024-57189
In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.... Read more
Affected Products : erxes- Published: Jun. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-57190
Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.... Read more
Affected Products : erxes- Published: Jun. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-48448
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail: from 0.0.0 before 1.0.5.... Read more
- Published: Jun. 11, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Denial of Service
-
7.2
HIGHCVE-2025-6005
A vulnerability classified as critical was found in kiCode111 like-girl 5.2.0. This vulnerability affects unknown code of the file /admin/aboutPost.php. The manipulation of the argument title/aboutimg/info1/info2/info3/btn1/btn2/infox1/infox2/infox3/infox... Read more
Affected Products : like-girl- Published: Jun. 12, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6006
A vulnerability, which was classified as critical, has been found in kiCode111 like-girl 5.2.0. This issue affects some unknown processing of the file /admin/ImgUpdaPost.php. The manipulation of the argument id/imgText/imgDatd/imgUrl leads to sql injectio... Read more
Affected Products : like-girl- Published: Jun. 12, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-5138
A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component PDF File Handler. The manipulation leads to cross site scripting. The attack can be launc... Read more
Affected Products :- Published: May. 25, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2023-25719
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiseControl.Client.exe h parameter. This results in reflected data and injection of malicious code into a downloaded ... Read more
Affected Products : control- Published: Feb. 13, 2023
- Modified: Jun. 19, 2025
-
9.8
CRITICALCVE-2023-25718
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (differen... Read more
Affected Products : control- Published: Feb. 13, 2023
- Modified: Jun. 19, 2025
-
0.0
NACVE-2024-58077
In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-pcm: don't use soc_pcm_ret() on .prepare callback commit 1f5664351410 ("ASoC: lower "no backend DAIs enabled for ... Port" log severity") ignores -EINVAL error message on comm... Read more
Affected Products : linux_kernel- Published: Mar. 06, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2024-56694
In the Linux kernel, the following vulnerability has been resolved: bpf: fix recursive lock when verdict program return SK_PASS When the stream_verdict program returns SK_PASS, it places the received skb into its own receive queue, but a recursive lock ... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2024
- Modified: Jun. 19, 2025
-
7.8
HIGHCVE-2024-46852
In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix off-by-one in CMA heap fault handler Until VM_DONTEXPAND was added in commit 1c1914d6e8c6 ("dma-buf: heaps: Don't track CMA dma-buf pages under RssFile") it was poss... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Jun. 19, 2025
-
5.5
MEDIUMCVE-2024-45025
In the Linux kernel, the following vulnerability has been resolved: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE copy_fd_bitmaps(new, old, count) is expected to copy the first count/BITS_PER_LONG bits from old->full_fds_bits[] and fil... Read more
Affected Products : linux_kernel- Published: Sep. 11, 2024
- Modified: Jun. 19, 2025
-
5.5
MEDIUMCVE-2024-43911
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL dereference at band check in starting tx ba session In MLD connection, link_data/link_conf are dynamically allocated. They don't point to vif->bss_conf. So, the... Read more
Affected Products : linux_kernel- Published: Aug. 26, 2024
- Modified: Jun. 19, 2025
-
3.3
LOWCVE-2024-43845
In the Linux kernel, the following vulnerability has been resolved: udf: Fix bogus checksum computation in udf_rename() Syzbot reports uninitialized memory access in udf_rename() when updating checksum of '..' directory entry of a moved directory. This ... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2024
- Modified: Jun. 19, 2025
-
5.5
MEDIUMCVE-2024-43835
In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix napi_skb_cache_put warning After the commit bdacf3e34945 ("net: Use nested-BH locking for napi_alloc_cache.") was merged, the following warning began to appear: WARNI... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2024
- Modified: Jun. 19, 2025
-
5.5
MEDIUMCVE-2024-36288
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated. This results in the following KASAN splat: KASAN: maybe wild-m... Read more
Affected Products : linux_kernel- Published: Jun. 21, 2024
- Modified: Jun. 19, 2025
-
5.5
MEDIUMCVE-2024-35927
In the Linux kernel, the following vulnerability has been resolved: drm: Check output polling initialized before disabling In drm_kms_helper_poll_disable() check if output polling support is initialized before disabling polling. If not flag this as a wa... Read more
Affected Products : linux_kernel- Published: May. 19, 2024
- Modified: Jun. 19, 2025
-
0.0
NACVE-2024-27410
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject iftype change with mesh ID change It's currently possible to change the mesh ID when the interface isn't yet in mesh mode, at the same time as changing it into mes... Read more
Affected Products : linux_kernel- Published: May. 17, 2024
- Modified: Jun. 19, 2025
-
5.5
MEDIUMCVE-2024-26829
In the Linux kernel, the following vulnerability has been resolved: media: ir_toy: fix a memleak in irtoy_tx When irtoy_command fails, buf should be freed since it is allocated by irtoy_tx, or there is a memleak.... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2024
- Modified: Jun. 19, 2025