NA - CVE-2025-0287 - Paragon Partition Manager version 7.9.1...
Paragon Partition Manager version 7.9.1 contains a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing...
NA - CVE-2025-0288 - Paragon Partition Manager version 7.9.1...
Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory vulnerability facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an...
NA - CVE-2025-0289 - Paragon Partition Manager version 17, both...
Paragon Partition Manager version 17, both community and Business versions, contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa...
Medium - CVE-2025-0678 - A flaw was found in grub2. When reading data...
A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer...
High - CVE-2025-1876 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in D-Link DAP-1562 1.10. Affected by this issue is the function http_request_parse of the component HTTP Header Handler. The...
NA - CVE-2025-25301 - Rembg is a tool to remove images background. In...
Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An...
NA - CVE-2025-25302 - Rembg is a tool to remove images background. In...
Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests...
NA - CVE-2025-25303 - The MouseTooltipTranslator Chrome extension...
The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vulnerable to SSRF attacks. The pdf.mjs script uses...
NA - CVE-2025-27421 - Abacus is a highly scalable and stateless...
Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in the Abacus server's Server-Sent Events (SSE) implementation. The issue...
NA - CVE-2025-27422 - FACTION is a PenTesting Report Generation and...
FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without...