4.6
CVE-2025-1368 - MicroWord eScan Antivirus mwav.conf ReadConfiguration buffer overflow
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects the function ReadConfiguration of the file /opt/MicroWorld/etc/mwav.conf. The manipulation of the argument BasePath leads to buffer overflow. Local access is requiโฆ
4.8
CVE-2025-1367 - MicroWord eScan Antivirus USB Password sprintf buffer overflow
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. This affects the function sprintf of the component USB Password Handler. The manipulation leads to buffer overflow. An attack has to be approached locally. The vendor was contacted early abouโฆ
4.8
CVE-2025-1366 - MicroWord eScan Antivirus VirusPopUp strcpy stack-based overflow
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this issue is the function strcpy of the component VirusPopUp. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been discloโฆ
6.8
CVE-2025-26465 - Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For โฆ
4.3
CVE-2024-25066 -
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.
5.4
CVE-2025-1391 - Keycloak-services: improper authorization in keycloak organization mapper allows unauthorized organโฆ
A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organizationโs domain pattern. This issue occurs at the mapper level, leading to misrepresentation in tokens. If an application relies on โฆ
7.8
CVE-2025-0591 - Out-of-bounds Read vulnerability in CX-Programmer
Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability.
4.8
CVE-2025-1365 - GNU elfutils eu-readelf readelf.c process_symtab buffer overflow
A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach this attack. The exploiโฆ
4.8
CVE-2025-1364 - MicroWord eScan Antivirus USB Protection Service passPrompt stack-based overflow
A vulnerability has been found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this vulnerability is the function passPrompt of the component USB Protection Service. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on thโฆ
4.9
CVE-2025-26779 - WordPress Keep Backup Daily plugin <= 2.1.0 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fahad Mahmood Keep Backup Daily keep-backup-daily allows Path Traversal.This issue affects Keep Backup Daily: from n/a through <= 2.1.0.