7.5

CVSS3.1

CVE-2025-32906 - Libsoup: out of bounds reads in soup_headers_parse_request()

A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:15 a.m.

6.5

CVSS3.1

CVE-2025-32912 - Libsoup: null pointer dereference in client when server omits the "nonce" parameter in an unauthor…

A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 11:08 p.m.

5.3

CVSS3.1

CVE-2025-32907 - Libsoup: denial of service in server when client requests a large amount of overlapping ranges wit…

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full…

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:35 a.m.

4.8

CVSS3.1

CVE-2025-29720 -

Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: June 18, 2025, 1:40 p.m.

7.4

CVSS3.1

CVE-2025-32914 - Libsoup: oob read on libsoup through function "soup_multipart_new_from_message" in soup-multipart.…

A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:15 a.m.

0.0

CVE-2025-32930 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: April 14, 2025, 3:15 p.m.

5.3

CVSS3.1

CVE-2025-32909 - Libsoup: null pointer dereference on libsoup through function "sniff_mp4" in soup-content-sniffer.c

A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 11:08 p.m.

6.5

CVSS3.1

CVE-2025-32910 - Libsoup: null pointer deference on libsoup via /auth/soup-auth-digest.c through "soup_auth_digest_…

A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 11:08 p.m.

9.1

CVSS3.1

CVE-2025-32931 -

DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.

πŸ“… Published: April 14, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 6:39 p.m.

8.6

CVSS4.0

CVE-2025-3542 - H3C Magic NX15/Magic NX400/Magic R3010 HTTP POST Request getsyncpppoecfg FCGI_WizardProtoProcess co…

A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014. This affects the function FCGI_WizardProtoProcess of the file /api/wizard/getsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command injecti…

πŸ“… Published: April 13, 2025, 11:31 p.m. πŸ”„ Last Modified: April 15, 2025, 6:39 p.m.
Total resulsts: 343935
Page 5373 of 34,394
Β« previous page Β» next page
Filters