NA - CVE-2025-27423 - Vim is an open source, command line text...
Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858,...
NA - CVE-2025-27498 - aes-gcm is a pure Rust implementation of the...
aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exposed even if the tag is incorrect. This is...
NA - CVE-2023-49031 - Directory Traversal (Local File Inclusion)...
Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information via a...
NA - CVE-2024-53384 - A DOM Clobbering vulnerability in tsup v8.3.4...
A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components
Medium - CVE-2025-0684 - A flaw was found in grub2. When performing a...
A flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses user-controlled parameters from the filesystem geometry to determine the...
Medium - CVE-2025-0685 - A flaw was found in grub2. When reading data...
A flaw was found in grub2. When reading data from a jfs filesystem, grub's jfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer...
Medium - CVE-2025-0686 - A flaw was found in grub2. When performing a...
A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses user-controlled parameters from the filesystem geometry to determine...
NA - CVE-2025-27370 - OpenID Connect Core through 1.0 errata set 2...
OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt authentication mechanism is used, a malicious Authorization Server could trick...
NA - CVE-2025-27371 - In certain IETF OAuth 2.0-related...
In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism is used, there are ambiguities in the audience values of JWTs sent to...