| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-55924 | Hig | 0.52 | 8.0 | 0.00 | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing… | ||
| CVE-2024-55921 | Hig | 0.42 | 7.5 | 0.00 | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing… | ||
| CVE-2024-53263 | Hig | 0.48 | — | 0.01 | Jan 14, 2025 | Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any… | ||
| CVE-2024-48858 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2025 | Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec. | ||
| CVE-2025-23042 | Hig | 0.42 | 7.5 | 0.01 | Jan 14, 2025 | Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the letter case of a blocked file or… | ||
| CVE-2025-21134 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… | ||
| CVE-2025-21133 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… | ||
| CVE-2025-21132 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2025-21131 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2025-21130 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2025-21129 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2025-21128 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2025-21127 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the… | ||
| CVE-2025-21122 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must… | ||
| CVE-2025-0474 | Hig | 0.43 | 7.7 | 0.00 | Jan 14, 2025 | Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23. | ||
| CVE-2024-52006 | Hig | 0.00 | 7.5 | 0.01 | Jan 14, 2025 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. Git defines a line-based protocol that is used to exchange information between Git and Git credential helpers.… | ||
| CVE-2024-50338 | Hig | 0.41 | 7.4 | 0.03 | Jan 14, 2025 | Git Credential Manager (GCM) is a secure Git credential helper built on .NET that runs on Windows, macOS, and Linux. The Git credential protocol is text-based over standard input/output, and consists of a series of lines of key-value pairs in the format `key=value`. Git's… | ||
| CVE-2024-48857 | Hig | 0.49 | 7.5 | 0.00 | Jan 14, 2025 | NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec. | ||
| CVE-2025-23052 | Hig | 0.47 | 7.2 | 0.01 | Jan 14, 2025 | Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | ||
| CVE-2025-23051 | Hig | 0.47 | 7.2 | 0.01 | Jan 14, 2025 | An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files. | ||
| CVE-2025-21607 | Hig | 0.42 | 7.5 | 0.01 | Jan 14, 2025 | Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amount of gas to make these calls fail but… | ||
| CVE-2025-21417 | Hig | 0.57 | 8.8 | 0.01 | Jan 14, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21413 | Hig | 0.57 | 8.8 | 0.01 | Jan 14, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21411 | Hig | 0.57 | 8.8 | 0.01 | Jan 14, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21409 | Hig | 0.57 | 8.8 | 0.01 | Jan 14, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21405 | Hig | 0.47 | 7.3 | 0.01 | Jan 14, 2025 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2025-21402 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Office OneNote Remote Code Execution Vulnerability | ||
| CVE-2025-21395 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Access Remote Code Execution Vulnerability | ||
| CVE-2025-21389 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-21382 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2025-21378 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Windows CSC Service Elevation of Privilege Vulnerability | ||
| CVE-2025-21372 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Microsoft Brokering File System Elevation of Privilege Vulnerability | ||
| CVE-2025-21370 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | ||
| CVE-2025-21366 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Access Remote Code Execution Vulnerability | ||
| CVE-2025-21365 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2025-21364 | Hig | 0.51 | 7.8 | 0.02 | Jan 14, 2025 | Microsoft Excel Security Feature Bypass Vulnerability | ||
| CVE-2025-21363 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2025-21362 | Hig | 0.55 | 8.4 | 0.01 | Jan 14, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-21361 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2025-21360 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | ||
| CVE-2025-21356 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2025-21354 | Hig | 0.55 | 8.4 | 0.01 | Jan 14, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-21348 | Hig | 0.47 | 7.2 | 0.02 | Jan 14, 2025 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2025-21346 | Hig | 0.46 | 7.1 | 0.01 | Jan 14, 2025 | Microsoft Office Security Feature Bypass Vulnerability | ||
| CVE-2025-21345 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2025-21344 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2025-21343 | Hig | 0.49 | 7.5 | 0.01 | Jan 14, 2025 | Windows Web Threat Defense User Service Information Disclosure Vulnerability | ||
| CVE-2025-21339 | Hig | 0.57 | 8.8 | 0.01 | Jan 14, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21338 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | GDI+ Remote Code Execution Vulnerability | ||
| CVE-2025-21335 | Hig | 0.63 | 7.8 | 0.01 | KEV | Jan 14, 2025 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
- risk 0.52cvss 8.0epss 0.00
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…
- risk 0.42cvss 7.5epss 0.00
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…
- risk 0.48cvss —epss 0.01
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any…
- risk 0.49cvss 7.5epss 0.01
Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.
- risk 0.42cvss 7.5epss 0.01
Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the letter case of a blocked file or…
- risk 0.51cvss 7.8epss 0.00
Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
- risk 0.51cvss 7.8epss 0.00
Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
- risk 0.51cvss 7.8epss 0.00
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the…
- risk 0.51cvss 7.8epss 0.00
Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…
- risk 0.43cvss 7.7epss 0.00
Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23.
- risk 0.00cvss 7.5epss 0.01
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. Git defines a line-based protocol that is used to exchange information between Git and Git credential helpers.…
- risk 0.41cvss 7.4epss 0.03
Git Credential Manager (GCM) is a secure Git credential helper built on .NET that runs on Windows, macOS, and Linux. The Git credential protocol is text-based over standard input/output, and consists of a series of lines of key-value pairs in the format `key=value`. Git's…
- risk 0.49cvss 7.5epss 0.00
NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.
- risk 0.47cvss 7.2epss 0.01
Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
- risk 0.47cvss 7.2epss 0.01
An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.
- risk 0.42cvss 7.5epss 0.01
Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amount of gas to make these calls fail but…
- risk 0.57cvss 8.8epss 0.01
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.47cvss 7.3epss 0.01
Visual Studio Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office OneNote Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Access Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.
- risk 0.51cvss 7.8epss 0.01
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows CSC Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Microsoft Brokering File System Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Access Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Microsoft Excel Security Feature Bypass Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Word Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Office Security Feature Bypass Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Web Threat Defense User Service Information Disclosure Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
GDI+ Remote Code Execution Vulnerability
- risk 0.63cvss 7.8epss 0.01
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability