Aggregator
【工具】美国国际开发署人员名单获取来源
9 months 3 weeks ago
美国国际开发署人员名单获取来源:https://contactout.com/
CVE-2025-25472 | DCMTK 3.6.9 DCM File denial of service
9 months 3 weeks ago
A vulnerability was found in DCMTK 3.6.9. It has been classified as problematic. This affects an unknown part of the component DCM File Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2025-25472. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-27113 | xmlsoft libxml2 up to 2.12.9/2.13.5 pattern.c xmlPatMatch null pointer dereference
9 months 3 weeks ago
A vulnerability was found in xmlsoft libxml2 up to 2.12.9/2.13.5 and classified as problematic. Affected by this issue is the function xmlPatMatch of the file pattern.c. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2025-27113. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-13743 | wonderplugin Wonder Video Embed Plugin up to 2.2 on WordPress Shortcode wonderplugin_video cross site scripting
9 months 3 weeks ago
A vulnerability has been found in wonderplugin Wonder Video Embed Plugin up to 2.2 on WordPress and classified as problematic. Affected by this vulnerability is the function wonderplugin_video of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-13743. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-25891 | D-Link DSL-3782 1.01 Packet destination/netmask/gateway denial of service
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in D-Link DSL-3782 1.01. Affected is an unknown function of the component Packet Handler. The manipulation of the argument destination/netmask/gateway leads to denial of service.
This vulnerability is traded as CVE-2025-25891. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-25896 | D-Link DSL-3782 1.01 Packet destination/netmask/gateway denial of service
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in D-Link DSL-3782 1.01. This issue affects some unknown processing of the component Packet Handler. The manipulation of the argument destination/netmask/gateway leads to denial of service.
The identification of this vulnerability is CVE-2025-25896. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-25892 | D-Link DSL-3782 1.01 Packet sstartip/sendip/dstartip/dendip denial of service
9 months 3 weeks ago
A vulnerability classified as problematic was found in D-Link DSL-3782 1.01. This vulnerability affects unknown code of the component Packet Handler. The manipulation of the argument sstartip/sendip/dstartip/dendip leads to denial of service.
This vulnerability was named CVE-2025-25892. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-26624 | pbatard rufus up to 4.6 cfgmgr32.dll untrusted search path
9 months 3 weeks ago
A vulnerability classified as critical has been found in pbatard rufus up to 4.6. This affects an unknown part in the library cfgmgr32.dll. The manipulation leads to untrusted search path.
This vulnerability is uniquely identified as CVE-2025-26624. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-25895 | D-Link DSL-3782 1.01 Packet public_type os command injection
9 months 3 weeks ago
A vulnerability was found in D-Link DSL-3782 1.01. It has been rated as critical. Affected by this issue is some unknown functionality of the component Packet Handler. The manipulation of the argument public_type leads to os command injection.
This vulnerability is handled as CVE-2025-25895. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-25893 | D-Link DSL-3782 1.01 Packet inIP/insPort/inePort/exsPort/exePort/protocol os command injection
9 months 3 weeks ago
A vulnerability was found in D-Link DSL-3782 1.01. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Packet Handler. The manipulation of the argument inIP/insPort/inePort/exsPort/exePort/protocol leads to os command injection.
This vulnerability is known as CVE-2025-25893. The attack can be launched remotely. There is no exploit available.
vuldb.com
New WinRAR version strips Windows metadata to increase privacy
9 months 3 weeks ago
WinRAR 7.10 was released yesterday with numerous features, such as larger memory pages, a dark mode, and the ability to fine-tune how Windows Mark-of-the-Web flags are propagated when extracting files. [...]
Lawrence Abrams
WinRAR 7.10 boosts Windows privacy by stripping MoTW data
9 months 3 weeks ago
WinRAR 7.10 was released yesterday with numerous features, such as larger memory pages, a dark mode, and the ability to fine-tune how Windows Mark-of-the-Web flags are propagated when extracting files. [...]
Lawrence Abrams
CVE-2025-25894 | D-Link DSL-3782 1.01 Packet samba_wg/samba_nbn os command injection
9 months 3 weeks ago
A vulnerability was found in D-Link DSL-3782 1.01. It has been classified as critical. Affected is an unknown function of the component Packet Handler. The manipulation of the argument samba_wg/samba_nbn leads to os command injection.
This vulnerability is traded as CVE-2025-25894. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-25471 | FFmpeg libavformat/mov.c null pointer dereference
9 months 3 weeks ago
A vulnerability was found in FFmpeg and classified as problematic. This issue affects some unknown processing of the file libavformat/mov.c. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2025-25471. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-25475 | DCMTK 3.6.9 DICOM File /libsrc/dcrleccd.cc null pointer dereference
9 months 3 weeks ago
A vulnerability has been found in DCMTK 3.6.9 and classified as problematic. This vulnerability affects unknown code in the library /libsrc/dcrleccd.cc of the component DICOM File Handler. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2025-25475. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-22645 | Rameez Iqbal Real Estate Manager Plugin up to 7.3 on WordPress excessive authentication
9 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Rameez Iqbal Real Estate Manager Plugin up to 7.3 on WordPress. This affects an unknown part. The manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability is uniquely identified as CVE-2025-22645. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-22654 | kodeshpa Simplified Plugin up to 1.0.6 on WordPress unrestricted upload
9 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in kodeshpa Simplified Plugin up to 1.0.6 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2025-22654. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-25467 | VideoLAN libx264 AAC File allocation of resources (Issue 75)
9 months 3 weeks ago
A vulnerability classified as critical was found in VideoLAN libx264. Affected by this vulnerability is an unknown functionality of the component AAC File Handler. The manipulation leads to allocation of resources.
This vulnerability is known as CVE-2025-25467. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-22650 | Erez Hadas-Sonnenschein Smartarget Plugin up to 1.4 on WordPress cross site scripting
9 months 3 weeks ago
A vulnerability classified as problematic has been found in Erez Hadas-Sonnenschein Smartarget Plugin up to 1.4 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-22650. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com