6.7
CVE-2025-21590 - Junos OS: An local attacker with shell access can execute arbitrary code
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrary code which can compromise an affectedโฆ
7.5
CVE-2025-27788 - Ruby JSON Parser has Out-of-bounds Read
JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of bound read, most likely resulting in a crash. Versions prior to 2.10.0 are not vulnerable. Version 2.10.2 fixes the problem. No known workarounds are avโฆ
8.8
CVE-2024-10838 - Integer Underflow in DDS_Security_Deserialize_ methods may lead to OOB read
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes orโฆ
5.3
CVE-2025-29904 -
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
5.2
CVE-2025-29903 -
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible
1.8
CVE-2024-13870 - Unauthenticated Firmware Downgrade in Bitdefender Box v1
An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX tโฆ
9.4
CVE-2024-13871 - Unauthenticated Command Injection in Bitdefender BOX v1
A command injection vulnerability exists in the /check_image_and_trigger_recoveryย API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to full remote code execโฆ
9.4
CVE-2024-13872 - Bitdefender Box Insecure Update Mechanism Vulnerability in libboxhermes.so
Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and netwโฆ
6.4
CVE-2025-1527 - ShopLentor โ WooCommerce Builder for Elementor & Gutenberg +20 Modules โ All in One Solution (formeโฆ
The ShopLentor โ WooCommerce Builder for Elementor & Gutenberg +20 Modules โ All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to a Stored DOM-Based Cross-Site Scripting via the plugin's Flash Sale Countdown module in all versions up to, and including, 3.1.0 due to insuffiโฆ
5.3
CVE-2025-2239 - Absolute Path Disclosure Vulnerability in Hillstone Next Generation FireWall
Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23.