Latest CVE Feed
-
5.9
MEDIUMCVE-2025-22641
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prem Tiwari FM Notification Bar allows Stored XSS. This issue affects FM Notification Bar: from n/a through 1.0.2.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2025-22206
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature.... Read more
Affected Products : js_jobs- Published: Feb. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-0825
cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.... Read more
Affected Products : cpp-httplib- Published: Feb. 04, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-9644
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the "bapply.cgi" endpoint instead o... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-9643
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2024-23690
The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary OS commands as root over Telnet by sending crafted "util backup_configura... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1020
Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-1019
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
-
7.3
HIGHCVE-2025-1018
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-1017
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary c... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1016
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these coul... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-1015
The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If a... Read more
Affected Products : thunderbird- Published: Feb. 04, 2025
- Modified: Mar. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-1014
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
-
6.5
MEDIUMCVE-2025-1013
A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 1... Read more
- Published: Feb. 04, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2025-1012
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2025-1011
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 13... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1010
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1009
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-0510
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.... Read more
Affected Products : thunderbird- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
-
4.8
MEDIUMCVE-2024-11623
Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.... Read more
Affected Products : authentik- Published: Feb. 04, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting