Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2025-21450 Cryptographic issue occurs due to use of insecure connection method while downloading. | 9.1 | CRITICAL | — | 0 |
| CVE-2025-21454 Transient DOS while processing received beacon frame. | 7.5 | HIGH | — | 0 |
| CVE-2025-21466 Memory corruption while processing a private escape command in an event trigger. | 7.8 | HIGH | — | 0 |
| CVE-2025-27043 Memory corruption while processing manipulated payload in video firmware. | 7.8 | HIGH | — | 0 |
| CVE-2025-27046 Memory corruption while processing multiple simultaneous escape calls. | 7.8 | HIGH | — | 0 |
| CVE-2025-27047 Memory corruption while processing the TESTPATTERNCONFIG escape path. | 7.8 | HIGH | — | 0 |
| CVE-2025-27050 Memory corruption while processing event close when client process terminates abruptly. | 7.8 | HIGH | — | 0 |
| CVE-2025-27052 Memory corruption while processing data packets in diag received from Unix clients. | 7.8 | HIGH | — | 0 |
| CVE-2025-27055 Memory corruption during the image encoding process. | 7.8 | HIGH | — | 0 |
| CVE-2025-27061 Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | 7.8 | HIGH | — | 0 |
| CVE-2025-47422 Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation vulnerability. When running as SYSTEM in certain configurations, Advanced Installer looks in standard-... | 7.5 | HIGH | — | 0 |
| CVE-2025-2793 IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting.... | 5.4 | MEDIUM | — | 0 |
| CVE-2025-2827 IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further... | 4.3 | MEDIUM | — | 0 |
| CVE-2025-36600 Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerability in an externally developed component. A high privileged attacker with local ac... | 8.2 | HIGH | — | 0 |
| CVE-2025-34099 An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vicidial_sales_viewer.php component when password encryption is enabled (a non-defau... | N/A | NONE | — | 0 |
| CVE-2025-3630 IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scrip... | 6.4 | MEDIUM | — | 0 |
| CVE-2025-6759 Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS | 7.8 | HIGH | — | 0 |
| CVE-2024-56468 IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could allow a remote user to cause a denial of service by sending an invalid HTTP request to the log reading service. | 7.5 | HIGH | — | 0 |
| CVE-2025-2670 IBM OpenPages 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points related to workflow feature of OpenPages. An authe... | 4.3 | MEDIUM | — | 0 |
| CVE-2025-52364 Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. This allows remote atta... | 7.5 | HIGH | — | 0 |
| CVE-2025-7204 In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sensitive user information. Specific API requests were found to return an overly ve... | 6.5 | MEDIUM | — | 0 |
| CVE-2025-0140 An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the Glo... | N/A | NONE | — | 0 |
| CVE-2025-24324 Integer overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege... | 2.8 | LOW | — | 0 |
| CVE-2025-3396 An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass gro... | 4.3 | MEDIUM | — | 0 |
| CVE-2025-4972 An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-l... | 2.7 | LOW | — | 0 |
| CVE-2025-6168 An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation ... | 2.7 | LOW | — | 0 |
| CVE-2025-6948 An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successfu... | 8.7 | HIGH | — | 0 |
| CVE-2025-5037 A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary cod... | 7.8 | HIGH | — | 0 |
| CVE-2025-53861 A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read... | 3.1 | LOW | — | 0 |
| CVE-2025-5040 A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive da... | 7.8 | HIGH | — | 0 |
| CVE-2025-6211 A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. This approach leads to ... | N/A | NONE | — | 0 |
| CVE-2025-46788 Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access. | 7.4 | HIGH | — | 0 |
| CVE-2025-46789 Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access. | 6.5 | MEDIUM | — | 0 |
| CVE-2025-49462 Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access. | 3.5 | LOW | — | 0 |
| CVE-2025-49463 Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via network access. | 6.5 | MEDIUM | — | 0 |
| CVE-2025-49464 Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access. | 6.5 | MEDIUM | — | 0 |
| CVE-2025-52473 liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementat... | 5.9 | MEDIUM | — | 0 |
| CVE-2025-53628 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to alloca... | 8.8 | HIGH | — | 0 |
| CVE-2025-53629 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in t... | 7.5 | HIGH | — | 0 |
| CVE-2025-53632 Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the path of the file to write is not checked, potentially lea... | 9.1 | CRITICAL | — | 0 |
| CVE-2025-53633 Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the size of the decoded content is not checked, potentially l... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-53634 Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes headers, but with no timeout set. With a slow loris attack, an attacker could cau... | 7.5 | HIGH | — | 0 |
| CVE-2025-7021 Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login creden... | 6.5 | MEDIUM | — | 0 |
| CVE-2025-24798 Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. This can lead to a degradation of s... | 4.3 | MEDIUM | — | 0 |
| CVE-2025-53637 Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be initiated by an atta... | 4.1 | MEDIUM | — | 0 |
| CVE-2025-31267 An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive... | 4.6 | MEDIUM | — | 0 |
| CVE-2025-53397 A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute una... | 5.4 | MEDIUM | — | 0 |
| CVE-2025-53509 A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privilege... | 6.5 | MEDIUM | — | 0 |
| CVE-2025-53515 A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least us... | 8.8 | HIGH | — | 0 |
| CVE-2025-3933 A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnera... | 5.3 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.