Latest CVE Feed
-
5.4
MEDIUMCVE-2024-55922
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Addit... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2024-55921
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Addit... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-55920
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Addit... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2024-55894
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Addit... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-55893
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Addit... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2024-55892
TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSR... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Server-Side Request Forgery
-
5.3
MEDIUMCVE-2024-55891
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYP... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Misconfiguration
-
8.5
HIGHCVE-2024-53263
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and ... Read more
Affected Products : git_large_file_storage- Published: Jan. 14, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-48858
Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.... Read more
Affected Products : qnx_software_development_platform- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Denial of Service
-
2.4
LOWCVE-2025-23074
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfile Extension allows Functionality Misuse.This issue affects Mediawiki - SocialProfile Extension: from 1.39.X before 1.39.11, from 1.41.... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2025-23073
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data. This issue briefly impacted the master branch of MediaWiki’s GlobalBlocking Ext... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-23072
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RefreshSpecial Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - RefreshSpecial Extensio... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-23042
Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the letter ca... Read more
Affected Products : gradio- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
5.8
MEDIUMCVE-2025-23041
Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2... Read more
Affected Products : umbraco_forms- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-21134
Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i... Read more
Affected Products : illustrator- Published: Jan. 14, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-21133
Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i... Read more
Affected Products : illustrator- Published: Jan. 14, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-21132
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Jan. 14, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-21131
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Jan. 14, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-21130
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Jan. 14, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-21129
Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic... Read more
- Published: Jan. 14, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Memory Corruption