Latest CVE Feed
-
0.0
NACVE-2025-37895
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix error handling path in bnxt_init_chip() WARN_ON() is triggered in __flush_work() if bnxt_init_chip() fails because we call cancel_work_sync() on dim work that has not been ... Read more
Affected Products : linux_kernel- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Race Condition
-
0.0
NACVE-2025-37894
In the Linux kernel, the following vulnerability has been resolved: net: use sock_gen_put() when sk_state is TCP_TIME_WAIT It is possible for a pointer of type struct inet_timewait_sock to be returned from the functions __inet_lookup_established() and _... Read more
Affected Products : linux_kernel- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2024-45641
IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.... Read more
- Published: May. 20, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-41228
VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to stea... Read more
Affected Products : esxi vcenter_server cloud_foundation telco_cloud_platform telco_cloud_infrastructure- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-41227
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the... Read more
Affected Products : workstation esxi fusion cloud_foundation telco_cloud_platform telco_cloud_infrastructure- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Denial of Service
-
6.8
MEDIUMCVE-2025-41226
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a... Read more
- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-41225
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.... Read more
- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-26086
An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time... Read more
Affected Products : management_system- Published: May. 20, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2023-33861
IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.... Read more
- Published: May. 20, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-4980
A vulnerability has been found in Netgear DGND3700 1.1.00.15_1.00.15NA and classified as problematic. This vulnerability affects unknown code of the file /currentsetting.htm of the component mini_http. The manipulation leads to information disclosure. The... Read more
- Published: May. 20, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Information Disclosure
-
7.2
HIGHCVE-2025-47941
TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor authentication (MFA) dialog presented during backend login can be bypassed due t... Read more
Affected Products : typo3- Published: May. 20, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-47940
TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalat... Read more
Affected Products : typo3- Published: May. 20, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-47939
TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of any file type, with the exception of those that are directly executable in a w... Read more
Affected Products : typo3- Published: May. 20, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Misconfiguration
-
3.8
LOWCVE-2025-47938
TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without ... Read more
Affected Products : typo3- Published: May. 20, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-47937
TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, when performing a database query involving multiple tables through the... Read more
Affected Products : typo3- Published: May. 20, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authorization
-
4.4
MEDIUMCVE-2025-47936
TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, Webhooks are inherently vulnerable to Cross-Site Request Forgery (CSRF), which can be exploited ... Read more
Affected Products : typo3- Published: May. 20, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-45862
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface.... Read more
- Published: May. 20, 2025
- Modified: May. 24, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-53359
An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.... Read more
Affected Products : zalo- Published: May. 20, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Information Disclosure
-
10.0
HIGHCVE-2025-4978
A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /BRS_top.html of the component Basic Authentication. The manipulation leads to improper authentication. It ... Read more
- Published: May. 20, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-4977
A vulnerability, which was classified as problematic, has been found in Netgear DGND3700 1.1.00.15_1.00.15NA. Affected by this issue is some unknown functionality of the file /BRS_top.html. The manipulation leads to information disclosure. The attack may ... Read more
- Published: May. 20, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Information Disclosure