8.6
CVE-2025-9120 - RCE vulnerability has been discovered in OpenTextโข Carbonite Safe Server Backup.
Improper Control of Generation of Code ('Code Injection') vulnerability in OpenTextโข Carbonite Safe Server Backup allows Code Injection.ย The vulnerability could be exploited through an open port, potentially allowing unauthorized access. This issue affects Carbonite Safe Server Backup: through 6โฆ
6.6
CVE-2025-69253 - free5GC vulnerable to improper error handling in NEF with information exposure
free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of the User Data Repository are affected by Improper Error Handling with Information Exposure. The NEF component reliably leaks internal parsing error details (e.g., invalid character โฆ
9.8
CVE-2025-69985 -
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can byโฆ
6.5
CVE-2025-67445 -
TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1) without sufficient bounds checking. When lighttpd s request size limit is not enfoโฆ
8.8
CVE-2025-63409 -
Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.
6.5
CVE-2026-3118 - Rhdh: graphql injection leading to platform-wide denial of service (dos) in rh developer hub orchesโฆ
A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation in GraphQL query handling. An authenticated user can inject specially crafted input into API requests, which disrupts backend query processing. This โฆ
6.6
CVE-2025-69252 - free5GC has Null Pointer Dereference in UDM, Leading to Service Panic
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 have a NULL Pointer Dereference vulnerability. Remote unauthenticated attackers can trigger a service panic (Denial of Service) by โฆ
9.1
CVE-2024-58041 - Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions
Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Smolder::DB::Developer usโฆ
6.6
CVE-2025-69251 - free5GC has Improper Input Validation in UDM, Leading to Information Exposure
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, remote attackers can inject control characters (e.g., %00) into the ueId parameter, triggering internal URL parsing errors (netโฆ
6.6
CVE-2025-69250 - free5GC has Improper Error Handling in UDM, Leading to Information Exposure
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the service reliably leaks detailed internal error messages (e.g., strconv.ParseInt parsing errors) to remote clients when procโฆ