CVE Notify
19.7K subscribers
4 photos
301K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2025-21452
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.

πŸŽ–@cveNotify
🚨 CVE-2025-21455
Memory corruption while submitting blob data to kernel space though IOCTL.

πŸŽ–@cveNotify
🚨 CVE-2025-21456
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.

πŸŽ–@cveNotify
🚨 CVE-2025-21457
Information disclosure while opening a fastrpc session when domain is not sanitized.

πŸŽ–@cveNotify
🚨 CVE-2025-21458
Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.

πŸŽ–@cveNotify
🚨 CVE-2025-21461
Memory corruption when programming registers through virtual CDM.

πŸŽ–@cveNotify
🚨 CVE-2025-7202
A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.

πŸŽ–@cveNotify
πŸ”₯1
🚨 CVE-2025-8556
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.

πŸŽ–@cveNotify
πŸ”₯1
🚨 CVE-2025-22469
OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1. An arbitrary OS command may be executed on the system with a certain non-administrative user privilege.

πŸŽ–@cveNotify
🚨 CVE-2025-22470
CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrary Lua script may be executed on the system with the root privilege.

πŸŽ–@cveNotify
🚨 CVE-2025-6013
Vault and Vault Enterprise’s (β€œVault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.

πŸŽ–@cveNotify
🚨 CVE-2025-7771
ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbitrary code in kernel context, resulting in privilege escalation and potential follow-on attacks, such as disabling security software or bypassing kernel-level protections. ThrottleStop.sys version 3.0.0.0 and possibly others are affected. Apply updates per vendor instructions.

πŸŽ–@cveNotify
🚨 CVE-2025-8620
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id.

πŸŽ–@cveNotify
πŸ”₯1
🚨 CVE-2025-46386
CWE-639 Authorization Bypass Through User-Controlled Key

πŸŽ–@cveNotify
🚨 CVE-2025-46387
CWE-639 Authorization Bypass Through User-Controlled Key

πŸŽ–@cveNotify
🚨 CVE-2025-46388
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

πŸŽ–@cveNotify
🚨 CVE-2025-5197
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` function. This function, responsible for converting TensorFlow weight names to PyTorch format, uses a regex pattern `/[^/]*___([^/]*)/` that can be exploited to cause excessive CPU consumption through crafted input strings due to catastrophic backtracking. The vulnerability affects versions up to 4.51.3 and is fixed in version 4.53.0. This issue can lead to service disruption, resource exhaustion, and potential API service vulnerabilities, impacting model conversion processes between TensorFlow and PyTorch formats.

πŸŽ–@cveNotify
🚨 CVE-2023-43091
A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.

πŸŽ–@cveNotify
🚨 CVE-2023-39176
A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.

πŸŽ–@cveNotify
🚨 CVE-2023-39179
A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.

πŸŽ–@cveNotify
🚨 CVE-2025-54253
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

πŸŽ–@cveNotify