A vulnerability was found in Ampere AmpereOne AC03, AmpereOne AC04 and AmpereOne M. It has been declared as critical. This affects an unknown function of the component UEFI-MM PCIe Driver. Executing manipulation can lead to out-of-bounds write.
This vulnerability is handled as CVE-2025-62863. The attack can only be done within the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in openedx edx-platform. It has been classified as critical. The impacted element is an unknown function. Performing manipulation results in missing authorization.
This vulnerability is known as CVE-2025-68270. Remote exploitation of the attack is possible. No exploit is available.
To fix this issue, it is recommended to deploy a patch.
A vulnerability was found in Ampere AmpereOne AC03, AmpereOne AC04 and AmpereOne M and classified as critical. The affected element is an unknown function of the component UEFI-MM MMCommunicate Service. Such manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2025-62864. Access to the local network is required for this attack to succeed. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in expr-lang expr up to 1.17.6 on Go and classified as problematic. Impacted is the function flatten/min/max/mean/median. This manipulation causes allocation of resources.
This vulnerability appears as CVE-2025-68156. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in D-Link DAP-1325 1.01. This issue affects some unknown processing of the file /cgi-bin/ExportSettings.sh of the component Export Settings Script. The manipulation results in missing authentication.
This vulnerability is reported as CVE-2023-53896. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability, which was classified as problematic, has been found in spip 4.1.10. This vulnerability affects unknown code of the component SVG File Parser. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2023-53900. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability classified as problematic was found in Arista EOS up to 4.31.0/4.31.8M/4.32.7M/4.33.4M/4.34.1F. This affects an unknown part of the component OSPFv3 Packet Handler. Executing manipulation can lead to resource consumption.
This vulnerability is registered as CVE-2025-8872. It is possible to launch the attack remotely. No exploit is available.
A vulnerability classified as critical has been found in vitejs vite-plugin-react up to 0.5.7. Affected by this issue is the function __vite_rsc_findSourceMapURL of the component React Server Component. Performing manipulation of the argument filename results in path traversal.
This vulnerability is cataloged as CVE-2025-68155. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in parse-server up to 8.6.1/9.1.0. Affected by this vulnerability is the function authData of the component Instagram Graph API. Such manipulation of the argument apiURL leads to server-side request forgery.
This vulnerability is listed as CVE-2025-68150. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Ampere AmpereOne AC03, AmpereOne AC04 and AmpereOne M. Affected is an unknown function of the component SMC Call Handler. This manipulation causes out-of-bounds write.
This vulnerability is tracked as CVE-2025-62862. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability labeled as very critical has been found in NVIDIA NeMo Framework. This impacts an unknown function of the component Model Loading. The manipulation results in deserialization.
This vulnerability is identified as CVE-2025-33212. The attack can be executed remotely. There is not any exploit available.
A vulnerability identified as critical has been detected in PimpMyLog 1.7.14. This affects an unknown function of the component Configuration Endpoint. The manipulation leads to improper authorization.
This vulnerability is referenced as CVE-2023-53895. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability categorized as critical has been discovered in NVIDIA Resiliency Extension on Linux. The impacted element is an unknown function of the component Checkpointing Core. Executing manipulation can lead to race condition.
The identification of this vulnerability is CVE-2025-33235. The attack can only be executed locally. There is no exploit available.
A vulnerability was found in NVIDIA NeMo Framework. It has been rated as critical. The affected element is an unknown function. Performing manipulation results in deserialization.
This vulnerability was named CVE-2025-33226. The attack needs to be approached locally. There is no available exploit.
A vulnerability was found in NVIDIA Resiliency Extension on Linux. It has been declared as critical. Impacted is an unknown function. Such manipulation leads to symlink following.
This vulnerability is uniquely identified as CVE-2025-33225. Local access is required to approach this attack. No exploit exists.