NA - CVE-2025-25198 - mailcow: dockerized is an open source...
mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to...
NA - CVE-2025-25199 - go-crypto-winnative Go crypto backend for...
go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41, calls to `cng.TLS1PRF` don't release...
NA - CVE-2025-25200 - Koa is expressive middleware for Node.js using...
Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the `X-Forwarded-Proto` and...
NA - CVE-2025-25741 - D-Link DIR-853 A1 FW1.20B07 was discovered to...
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the IPv6_PppoePassword parameter in the SetIPv6PppoeSettings module.
NA - CVE-2025-0937 - Nomad Community and Nomad Enterprise ("Nomad")...
Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.
NA - CVE-2025-1146 - CrowdStrike uses industry-standard TLS...
CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in...
NA - CVE-2025-1215 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory...
NA - CVE-2025-1216 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file...
NA - CVE-2025-25201 - Nitrokey 3 Firmware is the the firmware of...
Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled prior to 1.8.0, the PIV application could accept invalid keys for...
NA - CVE-2025-25205 - Audiobookshelf is a self-hosted audiobook and...
Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to...