CVE-2025-3155
- EPSS 0.13%
- Published 03.04.2025 14:15:46
- Last modified 12.08.2025 21:15:30
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
CVE-2024-40635
- EPSS 0.01%
- Published 17.03.2025 21:32:37
- Last modified 02.10.2025 01:51:43
containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow con...
CVE-2025-27363
- EPSS 67.14%
- Published 11.03.2025 13:28:31
- Last modified 07.05.2025 16:00:55
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed...
CVE-2025-24813
- EPSS 94.18%
- Published 10.03.2025 16:44:03
- Last modified 08.08.2025 17:56:59
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 1...
CVE-2025-26699
- EPSS 0.42%
- Published 06.03.2025 19:15:27
- Last modified 03.10.2025 00:32:38
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.
CVE-2025-27516
- EPSS 0.12%
- Published 05.03.2025 21:15:20
- Last modified 22.09.2025 18:49:36
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the ...
CVE-2025-26466
- EPSS 46.32%
- Published 28.02.2025 22:15:40
- Last modified 27.05.2025 16:15:31
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious cli...
CVE-2024-55581
- EPSS 0.07%
- Published 26.02.2025 22:15:14
- Last modified 07.04.2025 18:39:22
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS confi...
CVE-2025-0838
- EPSS 0.17%
- Published 21.02.2025 15:15:11
- Last modified 30.07.2025 18:10:35
There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to...
CVE-2025-26465
- EPSS 58.35%
- Published 18.02.2025 19:15:29
- Last modified 26.09.2025 07:15:41
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...