Search Results (323620 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-46993 1 Electron 1 Electron 2025-07-06 N/A
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 28.3.2, 29.3.3, and 30.0.3, the nativeImage.createFromPath() and nativeImage.createFromBuffer() functions call a function downstream that is vulnerable to a heap buffer overflow. An Electron program that uses either of the affected functions is vulnerable to a buffer overflow if an attacker is in control of the image's height, width, and contents. This issue has been patched in versions 28.3.2, 29.3.3, and 30.0.3. There are no workarounds for this issue.
CVE-2025-6942 1 Delinea 1 Secret Server 2025-07-06 3.8 Low
The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attacker to impersonate another distributed engine.
CVE-2025-39362 2 Mollie, Wordpress 2 Mollie Payments For Woocommerce, Wordpress 2025-07-06 6.5 Medium
Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce.This issue affects Mollie Payments for WooCommerce: from n/a through 8.0.2.
CVE-2025-6587 1 Docker 1 Docker Desktop 2025-07-06 N/A
System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.
CVE-2025-49618 1 Plesk 1 Obsidian 2025-07-06 5.8 Medium
In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.
CVE-2025-21879 1 Linux 1 Linux Kernel 2025-07-06 7.8 High
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free on inode when scanning root during em shrinking At btrfs_scan_root() we are accessing the inode's root (and fs_info) in a call to btrfs_fs_closing() after we have scheduled the inode for a delayed iput, and that can result in a use-after-free on the inode in case the cleaner kthread does the iput before we dereference the inode in the call to btrfs_fs_closing(). Fix this by using the fs_info stored already in a local variable instead of doing inode->root->fs_info.
CVE-2025-6022 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-5316 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-5104 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-4950 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-4694 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-3896 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-3524 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-3283 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-3156 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-3094 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2904 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2856 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2718 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2504 2025-07-05 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.