CVE-2025-30397
CVEs:CVE-2025-30397
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 23 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
CVEs:CVE-2025-30397
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
CVEs:CVE-2025-30397
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_11_23h2 | affected | microsoft | — | — |
| windows_11_24h2 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
| windows_server_2022_23h2 | affected | microsoft | — | — |
| windows_server_2025 | affected | microsoft | — | — |
Scripting Engine Memory Corruption Vulnerability
CVEs:CVE-2025-30397
CVEs:CVE-2025-32706
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVEs:CVE-2025-32706
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVEs:CVE-2025-32706
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_11_23h2 | affected | microsoft | — | — |
| windows_11_24h2 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
| windows_server_2022_23h2 | affected | microsoft | — | — |
| windows_server_2025 | affected | microsoft | — | — |
CVEs:CVE-2025-32709
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVEs:CVE-2025-32709
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVEs:CVE-2025-32709
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_11_23h2 | affected | microsoft | — | — |
| windows_11_24h2 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
| windows_server_2022_23h2 | affected | microsoft | — | — |
| windows_server_2025 | affected | microsoft | — | — |
CVEs:CVE-2025-30400
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
CVEs:CVE-2025-30400
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_11_23h2 | affected | microsoft | — | — |
| windows_11_24h2 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
| windows_server_2022_23h2 | affected | microsoft | — | — |
| windows_server_2025 | affected | microsoft | — | — |
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVEs:CVE-2025-30400
CVEs:CVE-2025-32701
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVEs:CVE-2025-32701
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_21h2 | affected | microsoft | — | — |
| windows_10_22h2 | affected | microsoft | — | — |
| windows_11_22h2 | affected | microsoft | — | — |
| windows_11_23h2 | affected | microsoft | — | — |
| windows_11_24h2 | affected | microsoft | — | — |
| windows_server_2008 | affected | microsoft | — | — |
| windows_server_2012 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
| windows_server_2022 | affected | microsoft | — | — |
| windows_server_2022_23h2 | affected | microsoft | — | — |
| windows_server_2025 | affected | microsoft | — | — |
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVEs:CVE-2025-32701
Updated chromium-browser-stable packages fix security vulnerabilities
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium-browser-stable | affected | Mageia:9 | chromium-browser-stable | — |
chromedriver-136.0.7103.113-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Tumbleweed | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
GHSA-vxhm-55mv-5fhx
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-4664
CVEs:CVE-2025-4664
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-4664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2025-4664
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
MINI-pm5g-pqrw-7hq9
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
MINI-m4qc-pc8f-gf27
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
CVEs:CVE-2025-29825
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVEs:CVE-2025-29825
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| edge_chromium | affected | microsoft | — | — |
ASB-A-400286977
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
DEBIAN-CVE-2025-48938
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-cli-go-gh | affected | Debian:12 | golang-github-cli-go-gh | — |
| golang-github-cli-go-gh | affected | Debian:13 | golang-github-cli-go-gh | — |
| golang-github-cli-go-gh | affected | Debian:14 | golang-github-cli-go-gh | — |
| golang-github-cli-go-gh-v2 | affected | Debian:13 | golang-github-cli-go-gh-v2 | — |
| golang-github-cli-go-gh-v2 | affected | Debian:14 | golang-github-cli-go-gh-v2 | — |
Ollama Server Vulnerable to Denial of Service (DoS) Attack in github.com/ollama/ollama
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| mods | affected | wolfi | mods | — |
| mods | affected | chainguard | mods | — |
| ollama-fips | affected | chainguard | ollama-fips | — |
| ollama/ollama | affected | github.com | github.com/ollama/ollama | — |
Ollama Server Vulnerable to Denial of Service (DoS) Attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ollama/ollama | affected | github.com | github.com/ollama/ollama | — |
Ollama Server Vulnerable to Denial of Service (DoS) Attack
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| mods | affected | chainguard | mods | — |
| mods | affected | wolfi | mods | — |
| ollama-fips | affected | chainguard | ollama-fips | — |
| ollama/ollama | affected | github.com | github.com/ollama/ollama | — |
DEBIAN-CVE-2025-3757
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-openpubkey-openpubkey | affected | Debian:13 | golang-github-openpubkey-openpubkey | — |
| golang-github-openpubkey-openpubkey | affected | Debian:14 | golang-github-openpubkey-openpubkey | — |
ASB-A-391928904
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...
CVEs:CVE-2024-12679
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_website_translator | affected | prisna | — | — |
CVEs:CVE-2024-12679
CVEs:CVE-2024-12680
The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...
CVEs:CVE-2024-12680
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| google_website_translator | affected | prisna | — | — |
A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers to craft requests that could be misinterpreted by backend servers. The iss...
CVEs:CVE-2025-4600
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| application_load_balancer | affected | — | — |
CVEs:CVE-2025-4600
CVEs:CVE-2025-0649
Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.
CVEs:CVE-2025-0649
Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.
CVEs:CVE-2025-0649
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow_serving | affected | — | — |
ASB-A-381276124
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-381274694
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-382314359
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-383349630
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2025-20963
Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.
CVEs:CVE-2025-20963
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.
CVEs:CVE-2025-20964
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20964
ASB-A-391932683
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-380438039
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
CVEs:CVE-2025-1079
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| web_designer | affected | — | — |
CVEs:CVE-2025-1079
ASB-A-383191754
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
ASB-A-385657784
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2025-2509
Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bou...
CVEs:CVE-2025-2509
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome_os | affected | — | — |
Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.
CVEs:CVE-2025-2509
CVEs:CVE-2025-27700
There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2025-27700
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-49739
In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-49739
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
ASB-A-369911749
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-330507809
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for...
CVEs:CVE-2025-26428
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26428
CVEs:CVE-2025-0077
In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2025-0077
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2024-56193
There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2024-56193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will be derefenced without prior NULL check, which can lead to local Temporary DoS or OOB...
CVEs:CVE-2025-27701
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-27701
ASB-A-394100273
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
ASB-A-394100476
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :linux_kernel:Qualcomm | affected | Android | :linux_kernel:Qualcomm | — |
PUB-A-238299155
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
PUB-A-384814655
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| :unknown: | affected | Android | :unknown: | — |
CVEs:CVE-2025-22425
In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CVEs:CVE-2025-22425
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2025-26421
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26421
In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2025-26424
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26424
In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local escalation of privilege on versions of Android where android.permission.MANAGE_DEFAULT_APPLICAT...
CVEs:CVE-2025-26425
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26425
CVEs:CVE-2023-35657
In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVEs:CVE-2023-35657
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26423
In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVEs:CVE-2025-26423
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26422
In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User in...
CVEs:CVE-2025-26422
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the default assistant application when a user-selected assistant is forcibly stopped due to a logic error in the code. This...
CVEs:CVE-2025-26444
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26444
CVEs:CVE-2025-26420
In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileg...
CVEs:CVE-2025-26420
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges ...
CVEs:CVE-2025-26436
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26436
In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2025-26440
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26440
In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device identifier with no additional execution privileges needed. User interaction is not needed for exploitation...
CVEs:CVE-2025-20665
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-20665
CVEs:CVE-2025-20668
In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: A...
CVEs:CVE-2025-20668
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-20979
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.
CVEs:CVE-2025-20979
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALP...
CVEs:CVE-2025-20671
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-20671
CVEs:CVE-2025-26430
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2025-26430
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26435
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privi...
CVEs:CVE-2025-26435
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26442
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic error in the code. This could lead to local information disclosure with no additional execution privil...
CVEs:CVE-2025-26442
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26429
In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2025-26429
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-20980
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.
CVEs:CVE-2025-20980
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
golang-github-prometheus-node_exporter-1.9.1-3.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-node_exporter | affected | openSUSE:Tumbleweed | golang-github-prometheus-node_exporter | — |
MINI-vjp8-rq2q-hm9c
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
MINI-v2v9-qc6q-3h55
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
GHSA-c82m-4wjj-w8fw
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2025-5280
Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-5280
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2025-5280
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
golang: Fix of CVE-2024-24790
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | TuxCare:AlmaLinux:9.2 | golang | — |
| golang-bin | affected | TuxCare:AlmaLinux:9.2 | golang-bin | — |
| golang-docs | affected | TuxCare:AlmaLinux:9.2 | golang-docs | — |
| golang-misc | affected | TuxCare:AlmaLinux:9.2 | golang-misc | — |
| golang-race | affected | TuxCare:AlmaLinux:9.2 | golang-race | — |
| golang-src | affected | TuxCare:AlmaLinux:9.2 | golang-src | — |
| golang-tests | affected | TuxCare:AlmaLinux:9.2 | golang-tests | — |
Moderate: go-toolset security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Rocky Linux:8 | delve | — |
| golang | affected | Rocky Linux:8 | golang | — |
| go-toolset | affected | Rocky Linux:8 | go-toolset | — |
MINI-jj63-c5j8-2fqv
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
MINI-4q7g-6mcj-x68c
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| setuptools | affected | PyPI | setuptools | — |
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ansible-operator | affected | chainguard | ansible-operator | — |
| ansible-operator-fips | affected | chainguard | ansible-operator-fips | — |
| aws-cli-2 | affected | chainguard | aws-cli-2 | — |
| aws-cli-2 | affected | wolfi | aws-cli-2 | — |
| awx | affected | chainguard | awx | — |
| azure-functions-host | affected | chainguard | azure-functions-host | — |
| checkov | affected | chainguard | checkov | — |
| checkov | affected | wolfi | checkov | — |
| dask-gateway | affected | wolfi | dask-gateway | — |
| dask-gateway | affected | chainguard | dask-gateway | — |
| datadog-agent | affected | wolfi | datadog-agent | — |
| datadog-agent | affected | chainguard | datadog-agent | — |
| datadog-agent-7.71 | affected | chainguard | datadog-agent-7.71 | — |
| datadog-agent-7.72 | affected | wolfi | datadog-agent-7.72 | — |
| datadog-agent-7.72 | affected | chainguard | datadog-agent-7.72 | — |
| datadog-agent-7.73 | affected | wolfi | datadog-agent-7.73 | — |
| datadog-agent-7.73 | affected | chainguard | datadog-agent-7.73 | — |
| datadog-agent-7.74 | affected | chainguard | datadog-agent-7.74 | — |
| datadog-agent-7.74 | affected | wolfi | datadog-agent-7.74 | — |
| datadog-agent-7.76 | affected | chainguard | datadog-agent-7.76 | — |
| datadog-agent-7.76 | affected | wolfi | datadog-agent-7.76 | — |
| datadog-agent-7.77 | affected | wolfi | datadog-agent-7.77 | — |
| datadog-agent-7.77 | affected | chainguard | datadog-agent-7.77 | — |
| datadog-agent-7.78 | affected | wolfi | datadog-agent-7.78 | — |
| datadog-agent-7.78 | affected | chainguard | datadog-agent-7.78 | — |
| datadog-agent-7.79 | affected | chainguard | datadog-agent-7.79 | — |
| datadog-agent-7.79 | affected | wolfi | datadog-agent-7.79 | — |
| datadog-agent-7.80 | affected | chainguard | datadog-agent-7.80 | — |
| datadog-agent-7.80 | affected | wolfi | datadog-agent-7.80 | — |
| datadog-agent-fips | affected | chainguard | datadog-agent-fips | — |
| datadog-agent-fips-7.71 | affected | chainguard | datadog-agent-fips-7.71 | — |
| datadog-agent-fips-7.72 | affected | chainguard | datadog-agent-fips-7.72 | — |
| datadog-agent-fips-7.73 | affected | chainguard | datadog-agent-fips-7.73 | — |
| datadog-agent-fips-7.74 | affected | chainguard | datadog-agent-fips-7.74 | — |
| datadog-agent-fips-7.76 | affected | chainguard | datadog-agent-fips-7.76 | — |
| datadog-agent-fips-7.77 | affected | chainguard | datadog-agent-fips-7.77 | — |
| datadog-agent-fips-7.78 | affected | chainguard | datadog-agent-fips-7.78 | — |
| datadog-agent-fips-7.79 | affected | chainguard | datadog-agent-fips-7.79 | — |
| datadog-agent-fips-7.80 | affected | chainguard | datadog-agent-fips-7.80 | — |
| emissary | affected | chainguard | emissary | — |
| emissary | affected | wolfi | emissary | — |
| graalvm-25 | affected | chainguard | graalvm-25 | — |
| jwt-tool | affected | chainguard | jwt-tool | — |
| jwt-tool | affected | wolfi | jwt-tool | — |
| kserve | affected | wolfi | kserve | — |
| kserve | affected | chainguard | kserve | — |
| kubeflow-katib | affected | chainguard | kubeflow-katib | — |
| kubeflow-katib | affected | wolfi | kubeflow-katib | — |
| localstack | affected | chainguard | localstack | — |
| nemo | affected | chainguard | nemo | — |
| nvidia-nsight-compute-13.1 | affected | chainguard | nvidia-nsight-compute-13.1 | — |
| nvidia-nsight-compute-13.2 | affected | chainguard | nvidia-nsight-compute-13.2 | — |
| nvidia-nsight-compute-13.3 | affected | chainguard | nvidia-nsight-compute-13.3 | — |
| pgadmin4 | affected | chainguard | pgadmin4 | — |
| pgadmin4-fips | affected | chainguard | pgadmin4-fips | — |
| py3.10-pytorch-cuda-12.3 | affected | chainguard | py3.10-pytorch-cuda-12.3 | — |
| py3.10-vllm-cuda-11.8 | affected | chainguard | py3.10-vllm-cuda-11.8 | — |
| py3.11-pytorch-cuda-11.8 | affected | chainguard | py3.11-pytorch-cuda-11.8 | — |
| py3.11-pytorch-cuda-12.3 | affected | chainguard | py3.11-pytorch-cuda-12.3 | — |
| py3-cassandra-medusa | affected | chainguard | py3-cassandra-medusa | — |
| py3-cassandra-medusa | affected | wolfi | py3-cassandra-medusa | — |
| py3-hashin | affected | chainguard | py3-hashin | — |
| py3-pipenv | affected | wolfi | py3-pipenv | — |
| py3-pipenv | affected | chainguard | py3-pipenv | — |
| pypy-3.10 | affected | wolfi | pypy-3.10 | — |
| pypy-3.10 | affected | chainguard | pypy-3.10 | — |
| pypy-3.11 | affected | chainguard | pypy-3.11 | — |
| pypy-3.11 | affected | wolfi | pypy-3.11 | — |
| request-1276 | affected | chainguard | request-1276 | — |
| setuptools | affected | PyPI | setuptools | — |
| setuptools | affected | PyPI | setuptools | — |
| setuptools | affected | PyPI | — | — |
| spamcheck | affected | chainguard | spamcheck | — |
| superset | affected | chainguard | superset | — |
| superset | affected | wolfi | superset | — |
| tensorflow-cpu-jupyter | affected | chainguard | tensorflow-cpu-jupyter | — |
| tensorflow-cpu-jupyter | affected | wolfi | tensorflow-cpu-jupyter | — |
| tensorflow-gpu-jupyter | affected | chainguard | tensorflow-gpu-jupyter | — |
| text-generation-inference | affected | chainguard | text-generation-inference | — |
| wazuh-manager | affected | chainguard | wazuh-manager | — |
| wazuh-manager-fips | affected | chainguard | wazuh-manager-fips | — |
Red Hat Security Advisory: protobuf security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | Red Hat:enterprise_linux:9::appstream | protobuf | — |
| protobuf | affected | Red Hat:enterprise_linux:9::crb | protobuf | — |
| protobuf-compiler | affected | Red Hat:enterprise_linux:9::appstream | protobuf-compiler | — |
| protobuf-compiler | affected | Red Hat:enterprise_linux:9::crb | protobuf-compiler | — |
| protobuf-compiler-debuginfo | affected | Red Hat:enterprise_linux:9::appstream | protobuf-compiler-debuginfo | — |
| protobuf-compiler-debuginfo | affected | Red Hat:enterprise_linux:9::crb | protobuf-compiler-debuginfo | — |
| protobuf-debuginfo | affected | Red Hat:enterprise_linux:9::crb | protobuf-debuginfo | — |
| protobuf-debuginfo | affected | Red Hat:enterprise_linux:9::appstream | protobuf-debuginfo | — |
| protobuf-debugsource | affected | Red Hat:enterprise_linux:9::appstream | protobuf-debugsource | — |
| protobuf-debugsource | affected | Red Hat:enterprise_linux:9::crb | protobuf-debugsource | — |
| protobuf-devel | affected | Red Hat:enterprise_linux:9::appstream | protobuf-devel | — |
| protobuf-devel | affected | Red Hat:enterprise_linux:9::crb | protobuf-devel | — |
| protobuf-lite | affected | Red Hat:enterprise_linux:9::appstream | protobuf-lite | — |
| protobuf-lite | affected | Red Hat:enterprise_linux:9::crb | protobuf-lite | — |
| protobuf-lite-debuginfo | affected | Red Hat:enterprise_linux:9::crb | protobuf-lite-debuginfo | — |
| protobuf-lite-debuginfo | affected | Red Hat:enterprise_linux:9::appstream | protobuf-lite-debuginfo | — |
| protobuf-lite-devel | affected | Red Hat:enterprise_linux:9::appstream | protobuf-lite-devel | — |
| protobuf-lite-devel | affected | Red Hat:enterprise_linux:9::crb | protobuf-lite-devel | — |
| python3-protobuf | affected | Red Hat:enterprise_linux:9::appstream | python3-protobuf | — |
| python3-protobuf | affected | Red Hat:enterprise_linux:9::crb | python3-protobuf | — |
Moderate: protobuf security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| protobuf | affected | AlmaLinux:9 | protobuf | — |
| protobuf-compiler | affected | AlmaLinux:9 | protobuf-compiler | — |
| protobuf-devel | affected | AlmaLinux:9 | protobuf-devel | — |
| protobuf-lite | affected | AlmaLinux:9 | protobuf-lite | — |
| protobuf-lite-devel | affected | AlmaLinux:9 | protobuf-lite-devel | — |
| python3-protobuf | affected | AlmaLinux:9 | python3-protobuf | — |
Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubernetes | affected | k8s.io | k8s.io/kubernetes | — |
golang: Fix of 2 CVEs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | TuxCare:AlmaLinux:9.2 | golang | — |
| golang-bin | affected | TuxCare:AlmaLinux:9.2 | golang-bin | — |
| golang-docs | affected | TuxCare:AlmaLinux:9.2 | golang-docs | — |
| golang-misc | affected | TuxCare:AlmaLinux:9.2 | golang-misc | — |
| golang-race | affected | TuxCare:AlmaLinux:9.2 | golang-race | — |
| golang-src | affected | TuxCare:AlmaLinux:9.2 | golang-src | — |
| golang-tests | affected | TuxCare:AlmaLinux:9.2 | golang-tests | — |
golang: Fix of 2 CVEs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | TuxCare:AlmaLinux:9.2 | golang | — |
| golang-bin | affected | TuxCare:AlmaLinux:9.2 | golang-bin | — |
| golang-docs | affected | TuxCare:AlmaLinux:9.2 | golang-docs | — |
| golang-misc | affected | TuxCare:AlmaLinux:9.2 | golang-misc | — |
| golang-race | affected | TuxCare:AlmaLinux:9.2 | golang-race | — |
| golang-src | affected | TuxCare:AlmaLinux:9.2 | golang-src | — |
| golang-tests | affected | TuxCare:AlmaLinux:9.2 | golang-tests | — |
Red Hat Security Advisory: gvisor-tap-vsock security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| gvisor-tap-vsock | affected | Red Hat:enterprise_linux:10.0 | gvisor-tap-vsock | — |
| gvisor-tap-vsock-debuginfo | affected | Red Hat:enterprise_linux:10.0 | gvisor-tap-vsock-debuginfo | — |
| gvisor-tap-vsock-debugsource | affected | Red Hat:enterprise_linux:10.0 | gvisor-tap-vsock-debugsource | — |
| gvisor-tap-vsock-gvforwarder | affected | Red Hat:enterprise_linux:10.0 | gvisor-tap-vsock-gvforwarder | — |
| gvisor-tap-vsock-gvforwarder-debuginfo | affected | Red Hat:enterprise_linux:10.0 | gvisor-tap-vsock-gvforwarder-debuginfo | — |
Red Hat Security Advisory: gvisor-tap-vsock security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| gvisor-tap-vsock | affected | Red Hat:enterprise_linux:9::appstream | gvisor-tap-vsock | — |
| gvisor-tap-vsock-debuginfo | affected | Red Hat:enterprise_linux:9::appstream | gvisor-tap-vsock-debuginfo | — |
| gvisor-tap-vsock-debugsource | affected | Red Hat:enterprise_linux:9::appstream | gvisor-tap-vsock-debugsource | — |
| gvisor-tap-vsock-gvforwarder | affected | Red Hat:enterprise_linux:9::appstream | gvisor-tap-vsock-gvforwarder | — |
| gvisor-tap-vsock-gvforwarder-debuginfo | affected | Red Hat:enterprise_linux:9::appstream | gvisor-tap-vsock-gvforwarder-debuginfo | — |
Important: gvisor-tap-vsock security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| gvisor-tap-vsock | affected | AlmaLinux:10 | gvisor-tap-vsock | — |
| gvisor-tap-vsock-gvforwarder | affected | AlmaLinux:10 | gvisor-tap-vsock-gvforwarder | — |
MINI-mqcj-qxjx-327q
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
MINI-447h-mrcw-2pw8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
Red Hat Security Advisory: delve and golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | Red Hat:enterprise_linux:10.0 | delve | — |
| delve-debuginfo | affected | Red Hat:enterprise_linux:10.0 | delve-debuginfo | — |
| delve-debugsource | affected | Red Hat:enterprise_linux:10.0 | delve-debugsource | — |
| golang | affected | Red Hat:enterprise_linux:10.0 | golang | — |
| golang-bin | affected | Red Hat:enterprise_linux:10.0 | golang-bin | — |
| golang-docs | affected | Red Hat:enterprise_linux:10.0 | golang-docs | — |
| golang-misc | affected | Red Hat:enterprise_linux:10.0 | golang-misc | — |
| golang-src | affected | Red Hat:enterprise_linux:10.0 | golang-src | — |
| golang-tests | affected | Red Hat:enterprise_linux:10.0 | golang-tests | — |
| go-toolset | affected | Red Hat:enterprise_linux:10.0 | go-toolset | — |
Moderate: delve and golang security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| delve | affected | AlmaLinux:10 | delve | — |
| golang | affected | AlmaLinux:10 | golang | — |
| golang-bin | affected | AlmaLinux:10 | golang-bin | — |
| golang-docs | affected | AlmaLinux:10 | golang-docs | — |
| golang-misc | affected | AlmaLinux:10 | golang-misc | — |
| golang-src | affected | AlmaLinux:10 | golang-src | — |
| golang-tests | affected | AlmaLinux:10 | golang-tests | — |
| go-toolset | affected | AlmaLinux:10 | go-toolset | — |
Fix CVE(s): CVE-2024-9287
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| idle-python3.6 | affected | TuxCare:Ubuntu:18.04 | idle-python3.6 | — |
| libpython3.6 | affected | TuxCare:Ubuntu:18.04 | libpython3.6 | — |
| libpython3.6-dev | affected | TuxCare:Ubuntu:18.04 | libpython3.6-dev | — |
| libpython3.6-minimal | affected | TuxCare:Ubuntu:18.04 | libpython3.6-minimal | — |
| libpython3.6-stdlib | affected | TuxCare:Ubuntu:18.04 | libpython3.6-stdlib | — |
| libpython3.6-testsuite | affected | TuxCare:Ubuntu:18.04 | libpython3.6-testsuite | — |
| python3.6 | affected | TuxCare:Ubuntu:18.04 | python3.6 | — |
| python3.6-dev | affected | TuxCare:Ubuntu:18.04 | python3.6-dev | — |
| python3.6-doc | affected | TuxCare:Ubuntu:18.04 | python3.6-doc | — |
| python3.6-examples | affected | TuxCare:Ubuntu:18.04 | python3.6-examples | — |
| python3.6-minimal | affected | TuxCare:Ubuntu:18.04 | python3.6-minimal | — |
| python3.6-venv | affected | TuxCare:Ubuntu:18.04 | python3.6-venv | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP6 | chromium | — |
| chromium | affected | openSUSE:Leap 15.6 | chromium | — |
chromedriver-136.0.7103.59-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Tumbleweed | chromium | — |
MINI-w8g2-284f-8w8j
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
MINI-62h9-wrjp-79x7
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.6 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP6 | chromium | — |
chromedriver-136.0.7103.92-1.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Tumbleweed | chromium | — |
GHSA-2vq3-r375-cjhg
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
DEBIAN-CVE-2025-4372
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2025-4372
CVEs:CVE-2025-4372
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2025-4372
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
GHSA-v9xg-688g-r69h
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2025-4096
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
golang: Fix of 2 CVEs
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | TuxCare:AlmaLinux:9.2 | golang | — |
| golang-bin | affected | TuxCare:AlmaLinux:9.2 | golang-bin | — |
| golang-docs | affected | TuxCare:AlmaLinux:9.2 | golang-docs | — |
| golang-misc | affected | TuxCare:AlmaLinux:9.2 | golang-misc | — |
| golang-race | affected | TuxCare:AlmaLinux:9.2 | golang-race | — |
| golang-src | affected | TuxCare:AlmaLinux:9.2 | golang-src | — |
| golang-tests | affected | TuxCare:AlmaLinux:9.2 | golang-tests | — |
GCP-2025-024 (High)
golang-github-prometheus-alertmanager-0.28.1-2.1 on GA media
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-prometheus-alertmanager | affected | openSUSE:Tumbleweed | golang-github-prometheus-alertmanager | — |
MINI-rpfg-vjph-9fr8
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
MINI-qpj9-jjr4-rv3j
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
golang-github-gorilla-csrf - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang-github-gorilla-csrf | affected | Debian:11 | golang-github-gorilla-csrf | — |
GCP-2025-025 (High)
CVEs:CVE-2025-22873
It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ...
CVEs:CVE-2025-22873
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
GHSA-w87c-v4h6-r3wj
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2025-5063
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVEs:CVE-2025-5063
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2025-5063
MINI-87q2-pfw9-w663
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
Ring: some aes functions may panic when overflow checking is enabled in ring in github.com/briansmith/ring
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| atuin | affected | chainguard | atuin | — |
| atuin | affected | wolfi | atuin | — |
| briansmith/ring | affected | github.com | github.com/briansmith/ring | — |
| buck2 | affected | wolfi | buck2 | — |
| buck2 | affected | chainguard | buck2 | — |
| cargo-audit | affected | chainguard | cargo-audit | — |
| cargo-audit | affected | wolfi | cargo-audit | — |
| deno | affected | chainguard | deno | — |
| deno | affected | wolfi | deno | — |
| fnm | affected | chainguard | fnm | — |
| kdash | affected | wolfi | kdash | — |
| kdash | affected | chainguard | kdash | — |
| linkerd2-proxy | affected | chainguard | linkerd2-proxy | — |
| linkerd2-proxy | affected | wolfi | linkerd2-proxy | — |
| linkerd-extension-init | affected | chainguard | linkerd-extension-init | — |
| linkerd-extension-init | affected | wolfi | linkerd-extension-init | — |
| lychee | affected | chainguard | lychee | — |
| lychee | affected | wolfi | lychee | — |
| ntpd-rs | affected | wolfi | ntpd-rs | — |
| ntpd-rs | affected | chainguard | ntpd-rs | — |
| nushell | affected | chainguard | nushell | — |
| nushell | affected | wolfi | nushell | — |
| oranda | affected | wolfi | oranda | — |
| oranda | affected | chainguard | oranda | — |
| parseable | affected | chainguard | parseable | — |
| parseable | affected | wolfi | parseable | — |
| pixi | affected | chainguard | pixi | — |
| pixi | affected | wolfi | pixi | — |
| qdrant | affected | wolfi | qdrant | — |
| qdrant | affected | chainguard | qdrant | — |
| rustls-ffi | affected | wolfi | rustls-ffi | — |
| rustls-ffi | affected | chainguard | rustls-ffi | — |
| rustup | affected | wolfi | rustup | — |
| rustup | affected | chainguard | rustup | — |
| rye | affected | chainguard | rye | — |
| rye | affected | wolfi | rye | — |
| samply | affected | chainguard | samply | — |
| samply | affected | wolfi | samply | — |
| sccache | affected | wolfi | sccache | — |
| sccache | affected | chainguard | sccache | — |
| sdp-k8s-injector | affected | wolfi | sdp-k8s-injector | — |
| sdp-k8s-injector | affected | chainguard | sdp-k8s-injector | — |
| shadowsocks-rust | affected | wolfi | shadowsocks-rust | — |
| shadowsocks-rust | affected | chainguard | shadowsocks-rust | — |
| sqlx | affected | chainguard | sqlx | — |
| sqlx | affected | wolfi | sqlx | — |
| tealdeer | affected | wolfi | tealdeer | — |
| tealdeer | affected | chainguard | tealdeer | — |
| uv | affected | wolfi | uv | — |
| uv | affected | chainguard | uv | — |
| wadm | affected | chainguard | wadm | — |
| wadm | affected | wolfi | wadm | — |
| wash | affected | chainguard | wash | — |
| wash | affected | wolfi | wash | — |
| wasmcloud | affected | chainguard | wasmcloud | — |
| wasmcloud | affected | wolfi | wasmcloud | — |
| wasm-pack | affected | wolfi | wasm-pack | — |
| wasm-pack | affected | chainguard | wasm-pack | — |
| wasmtime | affected | wolfi | wasmtime | — |
| wasmtime | affected | chainguard | wasmtime | — |
| xh | affected | wolfi | xh | — |
| xh | affected | chainguard | xh | — |
| zed | affected | wolfi | zed | — |
| zed | affected | chainguard | zed | — |
| zizmor | affected | wolfi | zizmor | — |
| zizmor | affected | chainguard | zizmor | — |
| zola | affected | wolfi | zola | — |
| zola | affected | chainguard | zola | — |
| ztunnel-1.25 | affected | chainguard | ztunnel-1.25 | — |
| ztunnel-fips-1.25 | affected | chainguard | ztunnel-fips-1.25 | — |
Tornado vulnerable to excessive logging caused by malformed multipart form data
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| airflow | affected | wolfi | airflow | — |
| airflow | affected | chainguard | airflow | — |
| airflow-3 | affected | chainguard | airflow-3 | — |
| airflow-3 | affected | wolfi | airflow-3 | — |
| airflow-core | affected | chainguard | airflow-core | — |
| dask-kubernetes | affected | wolfi | dask-kubernetes | — |
| dask-kubernetes | affected | chainguard | dask-kubernetes | — |
| grafana-oncall | affected | chainguard | grafana-oncall | — |
| grafana-oncall | affected | wolfi | grafana-oncall | — |
| jupyter-base-notebook | affected | wolfi | jupyter-base-notebook | — |
| jupyter-base-notebook | affected | chainguard | jupyter-base-notebook | — |
| kubeflow-pipelines-visualization-server | affected | chainguard | kubeflow-pipelines-visualization-server | — |
| kubeflow-pipelines-visualization-server | affected | wolfi | kubeflow-pipelines-visualization-server | — |
| tensorflow-cpu-jupyter | affected | wolfi | tensorflow-cpu-jupyter | — |
| tensorflow-cpu-jupyter | affected | chainguard | tensorflow-cpu-jupyter | — |
| tornado | affected | PyPI | tornado | — |
| tornado | affected | PyPI | tornado | — |
Tornado vulnerable to excessive logging caused by malformed multipart form data
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tornado | affected | PyPI | tornado | — |
GHSA-j84v-78j2-55gh
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
| firefox | affected | chainguard | firefox | — |
| firefox | affected | wolfi | firefox | — |
| firefox-esr | affected | chainguard | firefox-esr | — |
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2025-5283
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2025-5283
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2025-5283
DEBIAN-CVE-2025-5283
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| firefox-esr | affected | Debian:11 | firefox-esr | — |
| firefox-esr | affected | Debian:12 | firefox-esr | — |
| firefox-esr | affected | Debian:13 | firefox-esr | — |
| firefox-esr | affected | Debian:14 | firefox-esr | — |
| libvpx | affected | Debian:11 | libvpx | — |
| libvpx | affected | Debian:12 | libvpx | — |
| libvpx | affected | Debian:13 | libvpx | — |
| libvpx | affected | Debian:14 | libvpx | — |
| thunderbird | affected | Debian:11 | thunderbird | — |
| thunderbird | affected | Debian:12 | thunderbird | — |
| thunderbird | affected | Debian:13 | thunderbird | — |
| thunderbird | affected | Debian:14 | thunderbird | — |
Ollama Divide by Zero Vulnerability in github.com/ollama/ollama
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| k8sgpt | affected | chainguard | k8sgpt | — |
| k8sgpt | affected | wolfi | k8sgpt | — |
| mods | affected | wolfi | mods | — |
| mods | affected | chainguard | mods | — |
| ollama-fips | affected | chainguard | ollama-fips | — |
| ollama/ollama | affected | github.com | github.com/ollama/ollama | — |
GHSA-2pgc-776h-4jhr
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2025-4052
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
MINI-gvp4-jhm3-qrwf
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
MINI-c6h4-mvx2-c89h
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
GHSA-vvqw-r3vv-46ph
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2025-4050
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
GHSA-78m4-4wrg-v443
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2025-5065
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2025-5065
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2025-5065
GHSA-g3gr-c6vj-5j9j
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2025-5066
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2025-5066
Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Me...
CVEs:CVE-2025-5066
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2025-36504
When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVEs:CVE-2025-36504
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| big-ip_access_policy_manager | affected | f5 | — | — |
| big-ip_advanced_firewall_manager | affected | f5 | — | — |
| big-ip_advanced_web_application_firewall | affected | f5 | — | — |
| big-ip_analytics | affected | f5 | — | — |
| big-ip_application_acceleration_manager | affected | f5 | — | — |
| big-ip_application_security_manager | affected | f5 | — | — |
| big-ip_application_visibility_and_reporting | affected | f5 | — | — |
| big-ip_automation_toolchain | affected | f5 | — | — |
| big-ip_carrier-grade_nat | affected | f5 | — | — |
| big-ip_container_ingress_services | affected | f5 | — | — |
| big-ip_ddos_hybrid_defender | affected | f5 | — | — |
| big-ip_domain_name_system | affected | f5 | — | — |
| big-ip_edge_gateway | affected | f5 | — | — |
| big-ip_fraud_protection_service | affected | f5 | — | — |
| big-ip_global_traffic_manager | affected | f5 | — | — |
| big-ip_link_controller | affected | f5 | — | — |
| big-ip_local_traffic_manager | affected | f5 | — | — |
| big-ip_next_central_manager | affected | f5 | — | — |
| big-ip_next_cloud-native_network_functions | affected | f5 | — | — |
| big-ip_next_service_proxy_for_kubernetes | affected | f5 | — | — |
| big-ip_policy_enforcement_manager | affected | f5 | — | — |
| big-ip_ssl_orchestrator | affected | f5 | — | — |
| big-ip_webaccelerator | affected | f5 | — | — |
| big-ip_websafe | affected | f5 | — | — |
When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (E...
CVEs:CVE-2025-36557
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| big-ip_access_policy_manager | affected | f5 | — | — |
| big-ip_advanced_firewall_manager | affected | f5 | — | — |
| big-ip_analytics | affected | f5 | — | — |
| big-ip_application_acceleration_manager | affected | f5 | — | — |
| big-ip_application_security_manager | affected | f5 | — | — |
| big-ip_domain_name_system | affected | f5 | — | — |
| big-ip_fraud_protection_service | affected | f5 | — | — |
| big-ip_global_traffic_manager | affected | f5 | — | — |
| big-ip_link_controller | affected | f5 | — | — |
| big-ip_local_traffic_manager | affected | f5 | — | — |
| big-ip_next_cloud-native_network_functions | affected | f5 | — | — |
| big-ip_next_service_proxy_for_kubernetes | affected | f5 | — | — |
| big-ip_policy_enforcement_manager | affected | f5 | — | — |
CVEs:CVE-2025-36557
CVEs:CVE-2025-41399
When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not...
CVEs:CVE-2025-41399
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| big-ip_access_policy_manager | affected | f5 | — | — |
| big-ip_advanced_firewall_manager | affected | f5 | — | — |
| big-ip_advanced_web_application_firewall | affected | f5 | — | — |
| big-ip_analytics | affected | f5 | — | — |
| big-ip_application_acceleration_manager | affected | f5 | — | — |
| big-ip_application_security_manager | affected | f5 | — | — |
| big-ip_application_visibility_and_reporting | affected | f5 | — | — |
| big-ip_automation_toolchain | affected | f5 | — | — |
| big-ip_carrier-grade_nat | affected | f5 | — | — |
| big-ip_container_ingress_services | affected | f5 | — | — |
| big-ip_ddos_hybrid_defender | affected | f5 | — | — |
| big-ip_domain_name_system | affected | f5 | — | — |
| big-ip_edge_gateway | affected | f5 | — | — |
| big-ip_fraud_protection_service | affected | f5 | — | — |
| big-ip_global_traffic_manager | affected | f5 | — | — |
| big-ip_link_controller | affected | f5 | — | — |
| big-ip_local_traffic_manager | affected | f5 | — | — |
| big-ip_next_central_manager | affected | f5 | — | — |
| big-ip_next_cloud-native_network_functions | affected | f5 | — | — |
| big-ip_next_service_proxy_for_kubernetes | affected | f5 | — | — |
| big-ip_policy_enforcement_manager | affected | f5 | — | — |
| big-ip_ssl_orchestrator | affected | f5 | — | — |
| big-ip_webaccelerator | affected | f5 | — | — |
| big-ip_websafe | affected | f5 | — | — |
CVEs:CVE-2025-41414
When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVEs:CVE-2025-41414
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| big-ip_access_policy_manager | affected | f5 | — | — |
| big-ip_advanced_firewall_manager | affected | f5 | — | — |
| big-ip_advanced_web_application_firewall | affected | f5 | — | — |
| big-ip_analytics | affected | f5 | — | — |
| big-ip_application_acceleration_manager | affected | f5 | — | — |
| big-ip_application_security_manager | affected | f5 | — | — |
| big-ip_application_visibility_and_reporting | affected | f5 | — | — |
| big-ip_automation_toolchain | affected | f5 | — | — |
| big-ip_carrier-grade_nat | affected | f5 | — | — |
| big-ip_container_ingress_services | affected | f5 | — | — |
| big-ip_ddos_hybrid_defender | affected | f5 | — | — |
| big-ip_domain_name_system | affected | f5 | — | — |
| big-ip_edge_gateway | affected | f5 | — | — |
| big-ip_fraud_protection_service | affected | f5 | — | — |
| big-ip_global_traffic_manager | affected | f5 | — | — |
| big-ip_link_controller | affected | f5 | — | — |
| big-ip_local_traffic_manager | affected | f5 | — | — |
| big-ip_next_cloud-native_network_functions | affected | f5 | — | — |
| big-ip_next_service_proxy_for_kubernetes | affected | f5 | — | — |
| big-ip_policy_enforcement_manager | affected | f5 | — | — |
| big-ip_ssl_orchestrator | affected | f5 | — | — |
| big-ip_webaccelerator | affected | f5 | — | — |
| big-ip_websafe | affected | f5 | — | — |
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
CVEs:CVE-2025-4609
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2025-4609
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
CVEs:CVE-2025-4609
GHSA-vcfj-m4g8-j8jv
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2025-5067
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2025-5067
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2025-5067
Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVEs:CVE-2025-5067
GHSA-4g9c-v26v-gp27
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | wolfi | chromium | — |
| chromium | affected | chainguard | chromium | — |
DEBIAN-CVE-2025-5064
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2025-5064
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2025-5064
CVEs:CVE-2025-26438
In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges neede...
CVEs:CVE-2025-26438
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ...
CVEs:CVE-2024-11109
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| wp_google_review_slider | affected | ljapps | — | — |
CVEs:CVE-2024-11109
GHSA-2xf7-h82x-mhhg
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
DEBIAN-CVE-2025-4051
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
GHSA-hqjf-gj2q-64ch
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | chainguard | chromium | — |
| chromium | affected | wolfi | chromium | — |
CVEs:CVE-2025-5281
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)
CVEs:CVE-2025-5281
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2025-5281
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2025-20937
Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
CVEs:CVE-2025-20937
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20954
Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
CVEs:CVE-2025-20954
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20955
Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.
CVEs:CVE-2025-20955
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
CVEs:CVE-2025-20962
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20962
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.
CVEs:CVE-2025-20957
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20957
CVEs:CVE-2025-20953
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.
CVEs:CVE-2025-20953
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20961
Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.
CVEs:CVE-2025-20961
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20959
Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.
CVEs:CVE-2025-20959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20960
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
CVEs:CVE-2025-20960
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
CVEs:CVE-2025-20958
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.
CVEs:CVE-2025-20958
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | samsung | — | — |
In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CVEs:CVE-2025-26427
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26427
In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead to local escalation of privilege with no additional execut...
CVEs:CVE-2025-26426
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2025-26426
MINI-pr7h-3c9f-cq4r
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
MINI-hrvr-c39m-vc8r
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
MINI-gggg-9w3f-294q
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
MINI-35fx-43h7-4xmc
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
MINI-g966-998x-7g6c
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kube-apiserver-1.32 | affected | MinimOS | kube-apiserver-1.32 | — |
| kube-controller-manager-1.32 | affected | MinimOS | kube-controller-manager-1.32 | — |
| kubectl-1.32 | affected | MinimOS | kubectl-1.32 | — |
| kubectl-1.32-advanced-compat | affected | MinimOS | kubectl-1.32-advanced-compat | — |
| kube-proxy-1.32 | affected | MinimOS | kube-proxy-1.32 | — |
| kubernetes-1.32 | affected | MinimOS | kubernetes-1.32 | — |
| kube-scheduler-1.32 | affected | MinimOS | kube-scheduler-1.32 | — |
MINI-8wjq-7ggm-hq8f
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kubectl-1.31 | affected | MinimOS | kubectl-1.31 | — |
| kubectl-1.31-advanced-compat | affected | MinimOS | kubectl-1.31-advanced-compat | — |
| kubernetes-1.31 | affected | MinimOS | kubernetes-1.31 | — |
The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin chan...
CVEs:CVE-2023-2334
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| easy_digital_downloads_google_sheet_connector | affected | westerndeal | — | — |
| edd_gsheetconnector | affected | gsheetconnector | — | — |
CVEs:CVE-2023-2334
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.