6.9
CVE-2025-1868 - Information display on multiple products from Famatech Corp
Vulnerability of unauthorized exposure of confidential information affecting Advanced IP Scanner and Advanced Port Scanner. It occurs when these applications initiate a network scan, inadvertently sending the NTLM hash of the user performing the scan. This vulnerability can be exploited by intercepβ¦
6.5
CVE-2024-24778 - Apache StreamPipes: Resources Permission Escalation
Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixes the issue.
8.7
CVE-2025-0475 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.
7.8
CVE-2025-21424 - Use After Free in NPU
Memory corruption while calling the NPU driver APIs concurrently.
7.8
CVE-2024-53034 - Untrusted Pointer Dereference in DSP_Services
Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.
7.8
CVE-2024-53033 - Untrusted Pointer Dereference in DSP_Services
Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.
7.8
CVE-2024-53032 - Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive OS Platform
Memory corruption may occur in keyboard virtual device due to guest VM interaction.
7.8
CVE-2024-53031 - Improper Input Validation in Automotive OS Platform
Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.
7.8
CVE-2024-53030 - Improper Input Validation in Automotive OS Platform
Memory corruption while processing input message passed from FE driver.
7.8
CVE-2024-53029 - Improper Input Validation in Automotive OS Platform
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.