Latest CVE Feed
-
8.8
HIGHCVE-2025-5820
Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. T... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-5479
Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. An attacker must ... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-5478
Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. Authentication is not require... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-5477
Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sony XAV-AX8500 devices. An attacker must first obtain the ... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-5476
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerabili... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-5475
Sony XAV-AX8500 Bluetooth Packet Handling Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sony XAV-AX8500 devices. An attacker must first obtain the ability t... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6373
A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWizard1 of the file /goform/formWlSiteSurvey. The manipulation of the argument curTime leads to stack-based buffer overflo... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6372
A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formSetWizard1 of the file /goform/formSetWizard1. The manipulation of the argument curTime leads to stack-based buffer overflow. It is poss... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6371
A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation of the argument curTime leads to stack-based... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6370
A vulnerability classified as critical was found in D-Link DIR-619L 2.06B01. Affected by this vulnerability is the function formWlanGuestSetup of the file /goform/formWlanGuestSetup. The manipulation of the argument curTime leads to stack-based buffer ove... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6369
A vulnerability classified as critical has been found in D-Link DIR-619L 2.06B01. Affected is the function formdumpeasysetup of the file /goform/formdumpeasysetup. The manipulation of the argument curTime/config.save_network_enabled leads to stack-based b... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6368
A vulnerability was found in D-Link DIR-619L 2.06B01. It has been rated as critical. This issue affects the function formSetEmail of the file /goform/formSetEmail. The manipulation of the argument curTime/config.smtp_email_subject leads to stack-based buf... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6367
A vulnerability was found in D-Link DIR-619L 2.06B01. It has been declared as critical. This vulnerability affects unknown code of the file /goform/formSetDomainFilter. The manipulation of the argument curTime/sched_name_%d/url_%d leads to stack-based buf... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
6.9
MEDIUMCVE-2025-6365
A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical. Affected by this issue is the function set_pte_at in the library /include/arch-arm64/pgtable.h. The manipulation leads to resource con... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-6364
A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /adduser-exec.php. The manipulation of the argument Username leads to sql i... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
-
9.8
CRITICALCVE-2025-6363
A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /adding-exec.php. The manipulation of the argument ingname leads to sql injection. It is possible t... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 20, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6362
A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects some unknown processing of the file /editpro.php. The manipulation of the argument ID leads to sql injection. The attac... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6361
A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /adds.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated ... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
8.2
HIGHCVE-2025-48945
pycares is a Python module which provides an interface to c-ares. c-ares is a C library that performs DNS requests and name resolutions asynchronously. Prior to version 4.9.0, pycares is vulnerable to a use-after-free condition that occurs when a Channel ... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
3.1
LOWCVE-2023-5600
An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific referenc... Read more
Affected Products : gitlab- Published: Jun. 20, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Information Disclosure