Latest CVE Feed
- 
                                
                                
6.5
MEDIUMCVE-2025-11491
A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the att... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
0.0
NACVE-2023-53683
In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for crafted filesystem image can contain bogus lengt... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
4.5
MEDIUMCVE-2025-11489
A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads to symlink following. The attack can only be per... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-42706
A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 ... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
8.7
HIGHCVE-2025-9868
Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.... Read more
Affected Products : nexus_repository_manager- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Server-Side Request Forgery
 
 - 
                                
                                
8.6
HIGHCVE-2025-48981
An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection.... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Cryptography
 
 - 
                                
                                
0.0
NACVE-2023-53657
In the Linux kernel, the following vulnerability has been resolved: ice: Don't tx before switchdev is fully configured There is possibility that ice_eswitch_port_start_xmit might be called while some resources are still not allocated which might cause N... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
7.4
HIGHCVE-2025-9970
Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
7.5
HIGHCVE-2025-11488
A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Executing manipulation can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public... Read more
Affected Products : dir-852_firmware- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
0.0
NACVE-2023-53641
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: fix memory leak of remain_skbs hif_dev->remain_skb is allocated and used exclusively in ath9k_hif_usb_rx_stream(). It is implied that an allocated remain_skb is pr... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2023-53644
In the Linux kernel, the following vulnerability has been resolved: media: radio-shark: Add endpoint checks The syzbot fuzzer was able to provoke a WARNING from the radio-shark2 driver: ------------[ cut here ]------------ usb 1-1: BOGUS urb xfer, pipe... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
7.2
HIGHCVE-2025-11204
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.0.6.2 due to insufficient escaping on the user supplied parameter and... Read more
Affected Products : registrationmagic- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-43771
Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 allow remote attackers to inject arbitrary web scri... Read more
- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
5.3
MEDIUMCVE-2025-61672
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaki... Read more
Affected Products : synapse- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
0.0
NACVE-2023-53646
In the Linux kernel, the following vulnerability has been resolved: drm/i915/perf: add sentinel to xehp_oa_b_counters Arrays passed to reg_in_range_table should end with empty record. The patch solves KASAN detected bug with signature: BUG: KASAN: glob... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.1
MEDIUMCVE-2025-43830
Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 35 allows remote attackers to... Read more
- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-3448
Reflected cross-site scripting (XSS) vulnerabilities exist in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser ... Read more
Affected Products : automation_runtime- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
0.0
NACVE-2023-53648
In the Linux kernel, the following vulnerability has been resolved: ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer smatch error: sound/pci/ac97/ac97_codec.c:2354 snd_ac97_mixer() error: we previously assumed 'rac97' could be null (see line ... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2023-53650
In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: lcd_mipid: Fix an error handling path in mipid_spi_probe() If 'mipid_detect()' fails, we must free 'md' to avoid a memory leak.... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
0.0
NACVE-2023-53652
In the Linux kernel, the following vulnerability has been resolved: vdpa: Add features attr to vdpa_nl_policy for nlattr length check The vdpa_nl_policy structure is used to validate the nlattr when parsing the incoming nlmsg. It will ensure the attribu... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Misconfiguration