A data breach at the Pennsylvania State Education Association exposed the personal information of over 500,000 individuals. The Pennsylvania State Education Association (PSEA) suffered a data breach that impacted 517,487 individuals. PSEA is a labor union representing teachers, education support professionals, and other school employees in Pennsylvania. It advocates for public education, negotiates contracts, and […]
A vulnerability classified as critical was found in Xpdf up to 4.05. This vulnerability affects the function PostScript. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2025-2574. The attack can be initiated remotely. There is no exploit available.
A vulnerability classified as problematic has been found in KukuFM 1.12.7 on Android. This affects an unknown part of the file AndroidManifest.xml. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2025-25758. It is possible to launch the attack on the physical device. There is no exploit available.
A vulnerability was found in DESCOR INFOCAD up to 3.5.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Authorization Schema. The manipulation leads to improper authorization.
This vulnerability is handled as CVE-2025-26853. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in DESCOR INFOCAD up to 3.5.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2025-26852. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in D-Link DSL-3788 revA1 1.01R1B036_EU_EN. It has been classified as critical. Affected is the function COMM_MAKECustomMsg. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2024-57440. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Tenda AX12 22.03.01.46 and classified as critical. This issue affects the function sub_43fdcc of the file /goform/SetNetControlList. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-29215. The attack may be initiated remotely. There is no exploit available.
A vulnerability has been found in Tenda i12 1.0.0.10(3805) and classified as critical. This vulnerability affects the function formSetAutoPing. The manipulation of the argument ping1 leads to buffer overflow.
This vulnerability was named CVE-2025-29149. The attack can be initiated remotely. There is no exploit available.
Currently trending CVE - Hype Score: 3 - In the Linux kernel, the following vulnerability has been resolved:
tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().
Anderson Nascimento reported a use-after-free splat in tcp_twsk_unique()
with nice analysis.
Since commit ec94c2696f0b ("tcp/dccp: avoid one atomic ...
A vulnerability, which was classified as critical, was found in Esri Portal for ArcGIS 10.9.1/11.1/11.2/11.3/11.4. This affects an unknown part of the component Password Recovery. The manipulation leads to hard-coded credentials.
This vulnerability is uniquely identified as CVE-2025-2538. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in OpenBSD up to 7.5 Errata 014/7.6 Errata 005. Affected by this issue is some unknown functionality of the component wg. The manipulation leads to incorrect calculation of buffer size.
This vulnerability is handled as CVE-2025-30334. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is an unknown functionality of the file /goform/setModules of the component HTTP POST Request Handler. The manipulation of the argument wifiSSID leads to stack-based buffer overflow.
This vulnerability is known as CVE-2025-29217. The attack can be launched remotely. There is no exploit available.
A vulnerability classified as critical has been found in Tenda W18E 16.01.0.11. Affected is an unknown function of the file /goform/setModules of the component HTTP POST Request Handler. The manipulation of the argument wifiPwd leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-29218. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in kcp up to 0.26.2. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2025-29922. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in CentralSquare eTRAKiT.Net 3.2.1.77. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to sql injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-29980. The attack can be initiated remotely. There is no exploit available.