7.5
CVE-2025-53603 -
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.
9.4
CVE-2025-48952 - NetAlertX has Password Bypass Vulnerability due to Loose Comparison in PHP
NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to bypass password verification using SHA-256 magic hashes, due to loose comparison in PHP. In vulnerable versions of the application, a password comparisβ¦
8.7
CVE-2025-53366 - MCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of Service
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.9.4, a validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability (500 errors) until manually reβ¦
8.7
CVE-2025-53365 - MCP Python SDK has Unhandled Exception in Streamable HTTP Transport ,Leading to Denial of Service
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.10.0, if a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught ClosedResourceError on the server side, causinβ¦
5.3
CVE-2025-7070 - IROAD Dashcam Q9 MFA Pairing Request allocation of resources
A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler. The manipulation leads to allocation of resources. The attack needs to be done within the local nβ¦
4.8
CVE-2025-7069 - HDF5 H5FSsection.c H5FS__sect_link_size heap-based overflow
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed toβ¦
4.8
CVE-2025-7068 - HDF5 H5FL.c H5FL__malloc memory leak
A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation leads to memory leak. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
4.8
CVE-2025-7067 - HDF5 H5FScache.c H5FS__sinfo_serialize_node_cb heap-based overflow
A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_serialize_node_cb of the file src/H5FScache.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosβ¦
0.0
CVE-2025-53485 - SecurePoll: Unauthorized access to SetTranslationHandler allows arbitrary text changes
SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user to change election-related translation text. While partially broken in newer MediaWiki versions, the check is still missing. This issue affects Mediawiki - SecurePoll extensiβ¦
0.0
CVE-2025-53484 - SecurePoll: Multiple locations vulnerable to Cross-Site Scripting (XSS) via unescaped input
User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPagesTab() and getErrorsTab() (user-controllable page names) This allows attackers to inject JavaScript and compromise user sessions under certain conditions. This isβ¦