Latest CVE Feed
-
7.5
HIGHCVE-2025-55780
A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is... Read more
Affected Products :- Published: Sep. 23, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2025-43346
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 26, watchOS 26, iOS 18.7 and iPadOS 18.7, visionOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Processing a maliciously crafted media file may lead to une... Read more
- Published: Sep. 15, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-34186
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Du... Read more
- Published: Sep. 16, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2025-34185
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.... Read more
- Published: Sep. 16, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-34184
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST paramet... Read more
- Published: Sep. 16, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-34183
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass... Read more
- Published: Sep. 16, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Information Disclosure
-
9.3
CRITICALCVE-2025-34187
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers ca... Read more
- Published: Sep. 16, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-54942
A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality without prior authentication.... Read more
- Published: Aug. 30, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-9568
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.... Read more
- Published: Sep. 01, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-9570
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.... Read more
- Published: Sep. 01, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-9567
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.... Read more
- Published: Sep. 01, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-9569
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.... Read more
- Published: Sep. 01, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-54946
A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.... Read more
Affected Products : ehrd_ctms- Published: Aug. 30, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54944
An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution.... Read more
Affected Products : ehrd_ctms- Published: Aug. 30, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Misconfiguration
-
10.0
CRITICALCVE-2025-54945
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.... Read more
Affected Products : ehrd_ctms- Published: Aug. 30, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-54943
A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the absence of proper access control checks.... Read more
Affected Products : ehrd_ctms- Published: Aug. 30, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2025-7937
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially crafted image.... Read more
Affected Products :- Published: Sep. 19, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-6198
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.... Read more
Affected Products :- Published: Sep. 19, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-39816
In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: always use READ_ONCE() to read ring provided buffer lengths Since the buffers are mapped from userspace, it is prudent to use READ_ONCE() to read the value into a local v... Read more
Affected Products : linux_kernel- Published: Sep. 16, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-38709
In the Linux kernel, the following vulnerability has been resolved: loop: Avoid updating block size under exclusive owner Syzbot came up with a reproducer where a loop device block size is changed underneath a mounted filesystem. This causes a mismatch ... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2025
- Modified: Sep. 25, 2025
- Vuln Type: Race Condition