Latest CVE Feed
-
4.3
MEDIUMCVE-2025-22622
Age Verification for your checkout page. Verify your customer's identity 1.20.0 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/class-wc-integration... Read more
Affected Products :- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2024-13443
The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attribute... Read more
Affected Products :- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2024-11582
The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This make... Read more
Affected Products : subscribe2- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-1448
A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This issue affects some unknown processing of the file 9-12ping.php. The manipulation of the argument retry leads to command injection. The ... Read more
Affected Products :- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2024-57262
In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite, a related is... Read more
Affected Products : barebox- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2024-57261
In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-57258.... Read more
Affected Products : barebox- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-1447
A vulnerability was found in kasuganosoras Pigeon 1.0.177. It has been declared as critical. This vulnerability affects unknown code of the file /pigeon/imgproxy/index.php. The manipulation of the argument url leads to server-side request forgery. The att... Read more
Affected Products :- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2024-13508
The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthent... Read more
Affected Products : booking_package- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-27113
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.... Read more
Affected Products : libxml2- Published: Feb. 18, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Memory Corruption
-
6.8
MEDIUMCVE-2025-26624
Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated privileges (since the executable has be... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-25475
A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-25474
DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-25473
FFmpeg git master before commit c08d30 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-25472
A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-25471
FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-24928
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.... Read more
Affected Products : libxml2- Published: Feb. 18, 2025
- Modified: Mar. 21, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-22920
A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-22919
A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.... Read more
Affected Products : ffmpeg- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2024-57259
sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not considered in a size calculation.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2024-57258
Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk, via request2size, or because ptrdiff_t is mishandled on x86_64.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption