Medium - CVE-2025-0678 - A flaw was found in grub2. When reading data...
A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer...
High - CVE-2025-1876 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in D-Link DAP-1562 1.10. Affected by this issue is the function http_request_parse of the component HTTP Header Handler. The...
NA - CVE-2025-25301 - Rembg is a tool to remove images background. In...
Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An...
NA - CVE-2025-25302 - Rembg is a tool to remove images background. In...
Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests...
NA - CVE-2025-25303 - The MouseTooltipTranslator Chrome extension...
The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vulnerable to SSRF attacks. The pdf.mjs script uses...
NA - CVE-2025-27421 - Abacus is a highly scalable and stateless...
Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in the Abacus server's Server-Sent Events (SSE) implementation. The issue...
NA - CVE-2025-27422 - FACTION is a PenTesting Report Generation and...
FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without...
NA - CVE-2025-27423 - Vim is an open source, command line text...
Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858,...
NA - CVE-2025-27498 - aes-gcm is a pure Rust implementation of the...
aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exposed even if the tag is incorrect. This is...
NA - CVE-2023-49031 - Directory Traversal (Local File Inclusion)...
Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information via a...