Latest CVE Feed
-
8.1
HIGHCVE-2025-32409
Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory ... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Path Traversal
-
8.6
HIGHCVE-2025-0942
The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for unauthenticated users to trigger SQL Injection. This issue affects JPlatform before 10.0.6 and a PatchPlugin ... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3384
A vulnerability was found in 1000 Projects Human Resource Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /controller/employee.php. The manipulation of the argument email leads to sql injection. It is... Read more
Affected Products : human_resource_management_system- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3383
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search/search_sales.php. The manipulation of the argument Name leads to sql in... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-32034
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, a vulnerability in Apollo Router allowed queries with deeply nested and reused ... Read more
Affected Products : apollo_router- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-32033
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, the operation limits plugin uses unsigned 32-bit integers to track limit counte... Read more
Affected Products : apollo_router- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-32032
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router allowed queries with deeply nested and reused named fragments to be prohi... Read more
Affected Products : apollo_router- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-32031
Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive t... Read more
Affected Products : apollo_gateway- Published: Apr. 07, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-32030
Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive t... Read more
Affected Products : apollo_gateway- Published: Apr. 07, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Denial of Service
-
6.9
MEDIUMCVE-2025-32029
ts-asn1-der is a collection of utility classes to encode ASN.1 data following DER rule. Incorrect number DER encoding can lead to denial on service for absolute values in the range 2**31 -- 2**32 - 1. The arithmetic in the numBitLen didn't take into accou... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-31496
apollo-compiler is a query-based compiler for the GraphQL query language. Prior to 1.27.0, a vulnerability in Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. Named fragments were bei... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-3382
A vulnerability has been found in joey-zhou xiaozhi-esp32-server-java up to a14fe8115842ee42ab5c7a51706b8a85db5200b7 and classified as critical. This vulnerability affects the function update of the file /api/user/update. The manipulation of the argument ... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-3381
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMController.java of the component File Upload. The manipulation of the argument ID leads to path traversal. It is po... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Path Traversal
-
8.5
HIGHCVE-2025-29769
libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when it was not possible to determine the colour interpretation, known internally ... Read more
Affected Products : libvips- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-29594
A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorize... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.2
MEDIUMCVE-2025-29482
Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.... Read more
Affected Products : libheif- Published: Apr. 07, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2025-29481
Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf.... Read more
Affected Products : libbpf- Published: Apr. 07, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-29480
Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invalid and could not be reproduced.... Read more
Affected Products : gdal- Published: Apr. 07, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-29478
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.... Read more
Affected Products : fluent_bit- Published: Apr. 07, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-29087
In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer... Read more
Affected Products : sqlite- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption