Search

Search Results (330077 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-65886 2026-01-28 N/A
A shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted tensor shapes.
CVE-2025-63388 2 Dify, Langgenius 2 Dify, Dify 2026-01-28 9.1 Critical
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests. NOTE: the Supplier disputes this, providing the rationale of "sending requests with credentials does not provide any additional access compared to unauthenticated requests."
CVE-2025-58150 2026-01-28 8.8 High
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.
CVE-2025-56157 1 Langgenius 1 Dify 2026-01-28 9.8 Critical
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.
CVE-2025-28164 2026-01-28 5.5 Medium
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.
CVE-2025-13919 2026-01-28 5.4 Medium
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry.
CVE-2025-13918 2026-01-28 6.7 Medium
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
CVE-2025-13917 2026-01-28 7 High
WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
CVE-2025-68017 2 Antideo, Wordpress 2 Email Validator, Wordpress 2026-01-28 N/A
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Antideo Antideo Email Validator antideo-email-validator allows Blind SQL Injection.This issue affects Antideo Email Validator: from n/a through <= 1.0.10.
CVE-2025-65891 2026-01-28 N/A
A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_properties() with an invalid or negative device index.
CVE-2025-27063 1 Qualcomm 223 Csra6620, Csra6620 Firmware, Csra6640 and 220 more 2026-01-28 7.8 High
Memory corruption during video playback when video session open fails with time out error.
CVE-2025-57793 2026-01-28 N/A
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web application component. Crafted input can be executed as part of backend database queries. The issue is exploitable without authentication, significantly elevating the risk.
CVE-2025-68018 3 Ilmosys, Woocommerce, Wordpress 3 Order Listener For Woocommerce, Woocommerce, Wordpress 2026-01-28 9.4 Critical
Missing Authorization vulnerability in ilmosys Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Listener for WooCommerce: from n/a through <= 3.6.1.
CVE-2025-47319 1 Qualcomm 237 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 234 more 2026-01-28 6.7 Medium
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
CVE-2025-47322 1 Qualcomm 223 Ar8031, Ar8031 Firmware, Ar8035 and 220 more 2026-01-28 7.8 High
Memory corruption while handling IOCTL calls to set mode.
CVE-2026-24131 1 Pnpm 1 Pnpm 2026-01-28 5.5 Medium
pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A malicious npm package can specify `"directories": {"bin": "../../../../tmp"}` to escape the package directory, causing pnpm to chmod 755 files at arbitrary locations. This issue only affects Unix/Linux/macOS. Windows is not affected (`fixBin` gated by `EXECUTABLE_SHEBANG_SUPPORTED`). Version 10.28.2 contains a patch.
CVE-2025-47323 1 Qualcomm 357 Ar8035, Ar8035 Firmware, Csra6620 and 354 more 2026-01-28 7.8 High
Memory corruption while routing GPR packets between user and root when handling large data packet.
CVE-2025-47330 1 Qualcomm 447 Ar8031, Ar8031 Firmware, Ar8035 and 444 more 2026-01-28 5.5 Medium
Transient DOS while parsing video packets received from the video firmware.
CVE-2025-47331 1 Qualcomm 599 Ar8031, Ar8031 Firmware, Ar8035 and 596 more 2026-01-28 6.1 Medium
Information disclosure while processing a firmware event.
CVE-2025-47333 1 Qualcomm 479 Aqt1000, Aqt1000 Firmware, Ar8031 and 476 more 2026-01-28 6.6 Medium
Memory corruption while handling buffer mapping operations in the cryptographic driver.