7.5
CVE-2025-32906 - Libsoup: out of bounds reads in soup_headers_parse_request()
A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server.
6.5
CVE-2025-32912 - Libsoup: null pointer dereference in client when server omits the "nonce" parameter in an unauthorβ¦
A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.
5.3
CVE-2025-32907 - Libsoup: denial of service in server when client requests a large amount of overlapping ranges witβ¦
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a fullβ¦
4.8
CVE-2025-29720 -
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
7.4
CVE-2025-32914 - Libsoup: oob read on libsoup through function "soup_multipart_new_from_message" in soup-multipart.β¦
A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.
0.0
CVE-2025-32930 -
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.
5.3
CVE-2025-32909 - Libsoup: null pointer dereference on libsoup through function "sniff_mp4" in soup-content-sniffer.c
A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.
6.5
CVE-2025-32910 - Libsoup: null pointer deference on libsoup via /auth/soup-auth-digest.c through "soup_auth_digest_β¦
A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.
9.1
CVE-2025-32931 -
DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.
8.6
CVE-2025-3542 - H3C Magic NX15/Magic NX400/Magic R3010 HTTP POST Request getsyncpppoecfg FCGI_WizardProtoProcess coβ¦
A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014. This affects the function FCGI_WizardProtoProcess of the file /api/wizard/getsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command injectiβ¦