Total
79929 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-2463 | 1 Cdex | 1 Cdex | 2025-06-17 | N/A | 8.0 HIGH |
Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1. | |||||
CVE-2024-2465 | 1 Cdex | 1 Cdex | 2025-06-17 | N/A | 7.1 HIGH |
Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX application versions through 5.7.1. | |||||
CVE-2024-24027 | 1 Likeshop | 1 Likeshop | 2025-06-17 | N/A | 7.2 HIGH |
SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function DistributionMemberLogic::getFansLists. | |||||
CVE-2024-28396 | 1 Myprestamodules | 1 Orders \(csv\, Excel\) Export Pro | 2025-06-17 | N/A | 7.5 HIGH |
An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component. | |||||
CVE-2024-28735 | 1 Unit4 | 1 Financials By Coda | 2025-06-17 | N/A | 8.1 HIGH |
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request. | |||||
CVE-2023-50967 | 2 Fedoraproject, Latchset | 2 Fedora, Jose | 2025-06-17 | N/A | 7.5 HIGH |
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | |||||
CVE-2025-4948 | 2025-06-17 | N/A | 7.5 HIGH | ||
A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk. | |||||
CVE-2025-32914 | 2025-06-17 | N/A | 7.4 HIGH | ||
A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds. | |||||
CVE-2025-32913 | 2025-06-17 | N/A | 7.5 HIGH | ||
A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer dereference. This flaw allows a malicious HTTP peer to crash a libsoup client or server that uses this function. | |||||
CVE-2025-32906 | 2025-06-17 | N/A | 7.5 HIGH | ||
A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server. | |||||
CVE-2025-32049 | 2025-06-17 | N/A | 7.5 HIGH | ||
A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS). | |||||
CVE-2025-2784 | 2025-06-17 | N/A | 7.0 HIGH | ||
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server. | |||||
CVE-2025-48798 | 2025-06-17 | N/A | 7.3 HIGH | ||
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues. | |||||
CVE-2025-48797 | 2025-06-17 | N/A | 7.3 HIGH | ||
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow. | |||||
CVE-2024-50650 | 1 Timgreen | 1 Python Book | 2025-06-17 | N/A | 7.5 HIGH |
python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter. | |||||
CVE-2024-51141 | 1 Totolink | 2 A6000ub, A6000ub Firmware | 2025-06-17 | N/A | 7.8 HIGH |
An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components. | |||||
CVE-2024-33781 | 1 Csiro | 1 Multi-protocol Spdz | 2025-06-16 | N/A | 7.5 HIGH |
MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message. | |||||
CVE-2024-33782 | 1 Csiro | 1 Multi-protocol Spdz | 2025-06-16 | N/A | 7.5 HIGH |
MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message. | |||||
CVE-2024-38875 | 1 Djangoproject | 1 Django | 2025-06-16 | N/A | 7.5 HIGH |
An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of brackets. | |||||
CVE-2024-39614 | 1 Djangoproject | 1 Django | 2025-06-16 | N/A | 7.5 HIGH |
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters. |