Recent CVEs (Last 30 days)

5180 CVEs found

Rejected reason: Voluntarily withdrawn

Published: 2025-12-16
Products: 0
CVE-2025-14466
5.3 MEDIUM

A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthenticated attacker with network access to send specially-crafted HTTP requests th...

Published: 2025-12-16
Products: 0

An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An attacker can provid...

Published: 2025-12-16
Products: 1
Vendors:
malaterre

An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker ...

Published: 2025-12-16
Products: 1
Vendors:
malaterre

An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can pr...

Published: 2025-12-16
Products: 1
Vendors:
malaterre

An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can pr...

Published: 2025-12-16
Products: 1
Vendors:
malaterre
CVE-2025-64520
6.5 MEDIUM

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users shou...

Published: 2025-12-16
Products: 0

SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alpha-1, a nil pointer dereference vulnerability is in the SIPGO library's `NewResp...

Published: 2025-12-16
Products: 0

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Published: 2025-12-16
Products: 4
Vendors:
microsoft google linux apple

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Published: 2025-12-16
Products: 4
Vendors:
microsoft google linux apple
CVE-2025-34288
6.7 MEDIUM

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance ...

Published: 2025-12-16
Products: 3
Vendors:
nagios
CVE-2025-14700
9.9 CRITICAL

An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection...

Published: 2025-12-17
Products: 1
Vendors:
craftycontrol

An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.

Published: 2025-12-17
Products: 1
Vendors:
craftycontrol

Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

Published: 2025-12-17
Products: 0
CVE-2025-11009
5.1 MEDIUM

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all versions and Mitsubishi Electric GT Designer3 Version1 (GOT1000) all versions allows...

Published: 2025-12-17
Products: 0
CVE-2025-11369
4.3 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the g...

Published: 2025-12-17
Products: 0

A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of the file /admin/blog/comment/create. Such manipulation of the argument content lea...

Published: 2025-12-17
Products: 0
CVE-2025-14302
6.8 MEDIUM

Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe...

Published: 2025-12-17
Products: 0
CVE-2025-14303
6.8 MEDIUM

Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe devi...

Published: 2025-12-17
Products: 0
CVE-2025-13977
6.4 MEDIUM

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and incl...

Published: 2025-12-17
Products: 0