Search Results (343762 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-29316 1 Nodebb 1 Nodebb 2025-06-30 6.3 Medium
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.
CVE-2024-30161 1 Qt 1 Qt 2025-06-30 6.5 Medium
In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.)
CVE-2023-41313 1 Apache 1 Doris 2025-06-30 9.8 Critical
The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.
CVE-2024-1936 3 Debian, Mozilla, Redhat 7 Debian Linux, Thunderbird, Enterprise Linux and 4 more 2025-06-30 7.5 High
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when replying to the contaminated email message, the user might accidentally leak the confidential subject to a third-party. While this update fixes the bug and avoids future message contamination, it does not automatically repair existing contaminations. Users are advised to use the repair folder functionality, which is available from the context menu of email folders, which will erase incorrect subject assignments. This vulnerability affects Thunderbird < 115.8.1.
CVE-2025-5951 2025-06-28 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-6664 1 Codeastro 1 Patient Record Management System 2025-06-28 4.3 Medium
A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-53388 2025-06-28 N/A
Not used
CVE-2025-53387 2025-06-28 N/A
Not used
CVE-2025-53386 2025-06-28 N/A
Not used
CVE-2025-53385 2025-06-28 N/A
Not used
CVE-2025-53384 2025-06-28 N/A
Not used
CVE-2025-53383 2025-06-28 N/A
Not used
CVE-2025-53382 2025-06-28 N/A
Not used
CVE-2025-53381 2025-06-28 N/A
Not used
CVE-2025-53380 2025-06-28 N/A
Not used
CVE-2023-20597 1 Amd 202 Ryzen 3100, Ryzen 3100 Firmware, Ryzen 3300x and 199 more 2025-06-27 5.5 Medium
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
CVE-2023-20594 1 Amd 250 Epyc 7003, Epyc 7003 Firmware, Epyc 72f3 and 247 more 2025-06-27 4.4 Medium
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
CVE-2024-21925 2025-06-27 8.2 High
Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code execution.
CVE-2024-48646 1 Sage 2 1000, Sage Frp 1000 2025-06-27 8.1 High
An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files, such as HTML, scripts, or other executable content, that may be executed on the server, leading to further system compromise.
CVE-2024-48647 1 Sage 2 1000, Sage Frp 1000 2025-06-27 7.2 High
A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating the URL parameter in HTTP requests. The attacker can exploit this flaw to access sensitive information, including configuration files that may contain credentials and system settings, which could lead to further compromise of the server.