4.2
CVE-2025-58067 - Basecamp's Google Sign-In for Rails allowed redirects to protocol-relative URI
Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect a user to another origin if the "proceed_to" value in the session store is set to a protocol-relative URL. Normally the value of this URL is only written and read by the library o…
4.8
CVE-2025-9677 - Modo Legend of the Phoenix com.duige.hzw.multilingual AndroidManifest.xml improper export of androi…
A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown function of the file AndroidManifest.xml of the component com.duige.hzw.multilingual. The manipulation results in improper export of android application components. The attack needs to …
4.8
CVE-2025-9676 - NCSOFT Universe App com.ncsoft.universeapp AndroidManifest.xml improper export of android applicati…
A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidManifest.xml of the component com.ncsoft.universeapp. The manipulation leads to improper export of android application components. Local access is required to approach this attack. …
5.3
CVE-2025-58066 - DoS Vulnerability in ntpd-rs
nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. In versions between 1.2.0 and 1.6.1 inclusive servers which allow non-NTS traffic are affected by a denial of service vulnerability, where an attacker can induce a message storm between two NTP server…
4.8
CVE-2025-9675 - Voice Changer App com.tuyangkeji.changevoice AndroidManifest.xml improper export of android applica…
A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.tuyangkeji.changevoice. Executing manipulation can lead to improper export of android application components. It is possible to launch the…
4.8
CVE-2025-9674 - Transbyte Scooper News App com.hatsune.eagleee AndroidManifest.xml improper export of android appli…
A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.hatsune.eagleee. This manipulation causes improper export of android application components. The attack requires local …
4.8
CVE-2025-9673 - Kakao 헤이카카오 Hey Kakao App com.kakao.i.connect AndroidManifest.xml improper export of android applic…
A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.kakao.i.connect. The manipulation results in improper export of android application components. The atta…
4.8
CVE-2025-9672 - Rejseplanen App de.hafas.android.rejseplanen AndroidManifest.xml improper export of android applica…
A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file AndroidManifest.xml of the component de.hafas.android.rejseplanen. The manipulation leads to improper export of android application components. The attack needs to be performed loc…
4.8
CVE-2025-9671 - UAB Paytend App com.passport.cash AndroidManifest.xml improper export of android application compon…
A weakness has been identified in UAB Paytend App up to 2.1.9 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.passport.cash. Executing manipulation can lead to improper export of android application components. The attack needs to be launched locall…
6.9
CVE-2025-9670 - mixmark-io turndown commonmark-rules.js redos
A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been released t…