Latest CVE Feed
-
4.9
MEDIUMCVE-2025-24910
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the ... Read more
Affected Products : pentaho_business_analytics_server- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: XML External Entity
-
4.4
MEDIUMCVE-2025-24909
Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara Pentaho Bus... Read more
Affected Products : pentaho_business_analytics_server- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-24908
Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of ... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
6.8
MEDIUMCVE-2025-24907
Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of ... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-1704
ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful p... Read more
Affected Products : chrome_os- Published: Apr. 16, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-1568
Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Den... Read more
Affected Products : chrome_os- Published: Apr. 16, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-1566
DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.... Read more
Affected Products : chrome_os- Published: Apr. 16, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-0758
Overview The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732) Description Hitachi Vantara Pentaho Business Analytics Server prior to versio... Read more
Affected Products : pentaho_business_analytics_server- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Misconfiguration
-
4.4
MEDIUMCVE-2025-0757
Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara Pentaho Busi... Read more
Affected Products : pentaho_business_analytics_server- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-0756
Overview The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) De... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-43703
An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the attacker has no knowledge of an API key) through approaches such as scripts or the SRC attribute o... Read more
Affected Products : anki- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-32791
The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the permi... Read more
Affected Products : backstage- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Information Disclosure
-
3.7
LOWCVE-2025-32789
EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by their password hash. This flaw allows an attacker to make assumptions about the hash values of other users stored in the password column of... Read more
Affected Products : espocrm- Published: Apr. 16, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Information Disclosure
-
3.1
LOWCVE-2025-32787
SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerable to NULL dereference in `DeleteIPv6DefaultRouterInRA` called by `StorePacket`. Before dereferencing, `DeleteIPv6DefaultRouterInRA` do... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Denial of Service
-
4.7
MEDIUMCVE-2025-32783
XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured as closed from selecting "Prevent unregistered users to view pages" in the Administrations Rights. Th... Read more
Affected Products : xwiki- Published: Apr. 16, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Information Disclosure
-
10.0
CRITICALCVE-2025-32433
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH pr... Read more
Affected Products : staros network_services_orchestrator rv340_firmware rv340w_firmware rv345_firmware rv345p_firmware enterprise_nfv_infrastructure_software erlang\/otp rv160_firmware rv160w_firmware +26 more products- Actively Exploited
- Published: Apr. 16, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Authentication
-
8.2
HIGHCVE-2025-31478
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restrictions on email a... Read more
- Published: Apr. 16, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-25230
Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges.... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-3730
A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approach... Read more
Affected Products : pytorch- Published: Apr. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-3729
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file backup.php of the component Database Backup Handler. The manipulat... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection