Latest CVE Feed
-
7.5
HIGHCVE-2025-29070
A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never c... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Denial of Service
-
6.3
MEDIUMCVE-2025-29049
Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-29036
An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-29033
An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parameter.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-13941
A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ouch::archive::zip::convert_zip_date_time of the file zip.rs. The manipulation of the argument month leads to memory corruption. The atta... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2003-20001
An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2025-29069
A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations. NOTE: this is disputed by the Supplier beca... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Memory Corruption
-
9.3
CRITICALCVE-2025-3096
Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-31137
React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability in Remix/React Router that affects all Remix 2 and React Router 7 consumers using the Express adapter. Basically, this vulnerability all... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-26056
A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to ex... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-26055
An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-26054
Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-29208
CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php.... Read more
Affected Products : gym_management_system- Published: Apr. 01, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
4.6
MEDIUMCVE-2025-28132
A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session t... Read more
- Published: Apr. 01, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Authentication
-
4.6
MEDIUMCVE-2025-28131
A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to i... Read more
- Published: Apr. 01, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-27829
An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may be possible to interrupt multicast traffic on some of these interfaces. That could result in a denial of th... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-25041
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition a... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Path Traversal
-
0.0
NACVE-2025-21986
In the Linux kernel, the following vulnerability has been resolved: net: switchdev: Convert blocking notification chain to a raw one A blocking notification chain uses a read-write semaphore to protect the integrity of the chain. The semaphore is acquir... Read more
Affected Products : linux_kernel- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Race Condition
-
0.0
NACVE-2025-21985
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bound accesses [WHAT & HOW] hpo_stream_to_link_encoder_mapping has size MAX_HPO_DP2_ENCODERS(=4), but location can have size up to 6. As a result, it is nece... Read more
Affected Products : linux_kernel- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
4.7
MEDIUMCVE-2025-21984
In the Linux kernel, the following vulnerability has been resolved: mm: fix kernel BUG when userfaultfd_move encounters swapcache userfaultfd_move() checks whether the PTE entry is present or a swap entry. - If the PTE entry is present, move_present_pt... Read more
Affected Products : linux_kernel- Published: Apr. 01, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Race Condition