Latest CVE Feed
-
6.5
MEDIUMCVE-2025-28101
An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request.... Read more
Affected Products : flaskblog- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28009
A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.... Read more
Affected Products : dietiqa- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-26269
DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.... Read more
Affected Products : dragonfly- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-26268
DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.... Read more
Affected Products : dragonfly- Published: Apr. 17, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-25455
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-25454
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2024-55211
An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-53924
Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.... Read more
Affected Products : pycel- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
3.3
LOWCVE-2021-47671
In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the function directly returns without calling netif_rx(skb). This ... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2021-47670
In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the ... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2021-47669
In the Linux kernel, the following vulnerability has been resolved: can: vxcan: vxcan_xmit: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the canfd_frame cfd which aliases skb memory is accessed after th... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2021-47668
In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the ne... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2020-36789
In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but not always, the case), the ... Read more
Affected Products : linux_kernel- Published: Apr. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Race Condition
-
7.5
HIGHCVE-2025-32415
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a craft... Read more
Affected Products : libxml2- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-2947
IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command to elevate privileges to gain root access to the host operating system.... Read more
- Published: Apr. 17, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-29662
A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.... Read more
Affected Products : landchat- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-29661
Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.... Read more
Affected Products : litepubl_cms- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-29181
FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.... Read more
Affected Products : foxcms- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-29180
In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.... Read more
Affected Products : foxcms- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-29039
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Memory Corruption