Latest CVE Feed
-
6.5
MEDIUMCVE-2024-6875
A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API.... Read more
Affected Products : infinispan- Published: Mar. 28, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57083
A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.... Read more
Affected Products : redoc- Published: Mar. 28, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-56975
InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.... Read more
Affected Products : invoiceplane- Published: Mar. 28, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-38988
alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properti... Read more
Affected Products : unflatto- Published: Mar. 28, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-38985
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via in... Read more
Affected Products : depath- Published: Mar. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-24292
A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.... Read more
Affected Products : software_development_kit- Published: Mar. 28, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-2926
A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. ... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-2925
A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MM_realloc of the file src/H5MM.c. The manipulation of the argument mem leads to double free. The attack needs to be approached lo... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-2924
A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl_deserialize of the file src/H5HLcache.c. The manipulation of the argument free_block leads to heap-based buffer overflow. It is possib... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-2923
A vulnerability, which was classified as problematic, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5F_addr_encode_len of the file src/H5Fint.c. The manipulation of the argument pp leads to heap-based buffer overflow. Attack... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
2.0
LOWCVE-2025-2922
A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unknown functionality of the component BusyBox Shell. The manipulation leads to cleartext storage of sensitive information. It is possible... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Information Disclosure
-
6.6
MEDIUMCVE-2025-31164
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline.... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
6.6
MEDIUMCVE-2025-31163
Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-31162
Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2025-2921
A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the file /etc/passwd. The manipulation with the input Realtek leads to use of default password. It is possible to launch the attack on the... Read more
- Published: Mar. 28, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authentication
-
2.0
LOWCVE-2025-2920
A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This issue affects some unknown processing of the file /еtc/passwd. The manipulation leads to use of weak hash. It is possible to launch the attack on the physical dev... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cryptography
-
7.2
HIGHCVE-2025-2919
A vulnerability was found in Netis WF-2404 1.1.124EN. It has been declared as critical. This vulnerability affects unknown code of the component UART. The manipulation leads to hardware allows activation of test or debug logic at runtime. It is possible t... Read more
- Published: Mar. 28, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-2917
A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cms/file/read. The manipulation of the argument filePath leads to path traversal. It is possible to launch t... Read more
- Published: Mar. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-2916
A vulnerability, which was classified as critical, has been found in Aishida Call Center System up to 20250314. This issue affects some unknown processing of the file /doscall/weixin/open/amr2mp3. The manipulation of the argument File leads to command inj... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-2915
A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__accum_free of the file src/H5Faccum.c. The manipulation of the argument overlap_size leads to heap-based buffer overflow. Attacking loca... Read more
Affected Products : hdf5- Published: Mar. 28, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption