Latest CVE Feed
-
5.9
MEDIUMCVE-2025-53605
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.... Read more
Affected Products : protobuf- Published: Jul. 05, 2025
- Modified: Jul. 08, 2025
-
4.0
MEDIUMCVE-2025-53604
The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header.... Read more
Affected Products :- Published: Jul. 05, 2025
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2025-53603
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.... Read more
Affected Products :- Published: Jul. 05, 2025
- Modified: Jul. 08, 2025
-
8.1
HIGHCVE-2025-43711
Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications.... Read more
Affected Products :- Published: Jul. 05, 2025
- Modified: Jul. 08, 2025
-
9.3
CRITICALCVE-2025-26850
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.... Read more
Affected Products : kace_systems_management_appliance- Published: Jul. 05, 2025
- Modified: Jul. 08, 2025
-
9.4
CRITICALCVE-2025-48952
NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to bypass password verification using SHA-256 magic hashes, due to loose comparison in PHP. In vulnerable vers... Read more
Affected Products : netalertx- Published: Jul. 04, 2025
- Modified: Aug. 06, 2025
-
5.3
MEDIUMCVE-2025-7070
A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler. The manipulation leads to allocation of resources. Th... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
8.7
HIGHCVE-2025-53366
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.9.4, a validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service u... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
8.7
HIGHCVE-2025-53365
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.10.0, if a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught Cl... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
5.5
MEDIUMCVE-2025-7069
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the l... Read more
Affected Products : hdf5- Published: Jul. 04, 2025
- Modified: Jul. 09, 2025
-
5.5
MEDIUMCVE-2025-7068
A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation leads to memory leak. Attacking locally is a requirement. The exploit has been discl... Read more
Affected Products : hdf5- Published: Jul. 04, 2025
- Modified: Jul. 09, 2025
-
5.3
MEDIUMCVE-2025-53602
Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
5.5
MEDIUMCVE-2025-7067
A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_serialize_node_cb of the file src/H5FScache.c. The manipulation leads to heap-based buffer overflow. Local access is required to approa... Read more
Affected Products : hdf5- Published: Jul. 04, 2025
- Modified: Jul. 09, 2025
-
7.5
HIGHCVE-2025-53485
SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This ... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2025-53484
User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPagesTab() and getErrorsTab() (user-controllable page names) This allows attackers to inject JavaScript and compromise user se... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
8.8
HIGHCVE-2025-53483
ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF tokens, allowing attackers to trigger sensitive actions if an admin visits a malicious site. This issue affects Mediawiki - SecurePoll ... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.1
MEDIUMCVE-2025-53482
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - IPInfo Extension: from 1.39.X b... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2025-53481
Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Allocation.This issue affects Mediawiki - IPInfo Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.4... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
4.8
MEDIUMCVE-2025-52497
Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.... Read more
- Published: Jul. 04, 2025
- Modified: Jul. 17, 2025
-
7.8
HIGHCVE-2025-52496
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.... Read more
Affected Products : mbedtls- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025