Search Results (41045 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-23255 1 Nvidia 1 Cuda Toolkit 2025-10-06 3.3 Low
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary where a user may cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability may lead to a partial denial of service.
CVE-2025-3193 1 Algolia 1 Algoliasearch-helper 2025-10-05 7.5 High
Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is caught, code injected into the user-supplied search parameter may be exeucted. This is related to but distinct from the issue reported in [CVE-2021-23433](https://security.snyk.io/vuln/SNYK-JS-ALGOLIASEARCHHELPER-1570421). **NOTE:** This vulnerability is not exploitable in the default configuration of InstantSearch since searchParameters are not modifiable by users.
CVE-2024-33577 1 Siemens 2 Simcenter Femap, Simcenter Nastran 2025-10-03 7.8 High
A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.
CVE-2024-32635 1 Siemens 3 Jt2go, Parasolid, Teamcenter Visualization 2025-10-03 7.8 High
A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.10), Teamcenter Visualization V2312 (All versions < V2312.0005). The affected applications contain an out of bounds read past the unmapped memory region while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
CVE-2024-32636 1 Siemens 3 Jt2go, Parasolid, Teamcenter Visualization 2025-10-03 7.8 High
A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.10), Teamcenter Visualization V2312 (All versions < V2312.0005). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
CVE-2024-26275 1 Siemens 3 Jt2go, Parasolid, Teamcenter Visualization 2025-10-03 7.8 High
A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
CVE-2024-34085 1 Siemens 2 Jt2go, Teamcenter Visualization 2025-10-03 7.8 High
A vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions < V14.1.0.13), Teamcenter Visualization V14.2 (All versions < V14.2.0.10), Teamcenter Visualization V14.3 (All versions < V14.3.0.7), Teamcenter Visualization V2312 (All versions < V2312.0001). The affected applications contain a stack overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process.
CVE-2025-30176 1 Siemens 5 Simatic Pcs Neo, Sinec Nms, Sinema Remote Connect and 2 more 2025-10-03 7.5 High
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions), User Management Component (UMC) (All versions < V2.15.1.1). Affected products contain a out of bound read buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.
CVE-2025-30174 1 Siemens 4 Sinec Nms, Sinema Remote Connect, Totally Integrated Automation Portal and 1 more 2025-10-03 7.5 High
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions), User Management Component (UMC) (All versions < V2.15.1.1). Affected products contain a out of bound read buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.
CVE-2025-55847 1 Wavlink 3 M86x3a V240730, Wl-wn586x3a, Wl-wn586x3a Firmware 2025-10-03 8.8 High
Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerability arises because the Cookie parameter does not properly validate the length of input data. Attackers can exploit this to execute arbitrary code or cause a denial of service (DoS) on the system
CVE-2025-36202 1 Ibm 2 Webmethods, Webmethods Integration 2025-10-03 7.5 High
IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the improper validation of format string strings passed as an argument from an external source.
CVE-2024-33058 1 Qualcomm 379 Aqt1000, Aqt1000 Firmware, Ar8035 and 376 more 2025-10-03 7.5 High
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
CVE-2024-33035 1 Qualcomm 181 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 178 more 2025-10-03 8.4 High
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
CVE-2024-33016 1 Qualcomm 669 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 666 more 2025-10-03 6.8 Medium
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23364 1 Qualcomm 359 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 356 more 2025-10-03 7.5 High
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
CVE-2024-23358 1 Qualcomm 107 205 Mobile Platform, 205 Mobile Platform Firmware, Apq8017 and 104 more 2025-10-03 7.5 High
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
CVE-2024-23359 1 Qualcomm 324 205 Mobile Platform, 205 Mobile Platform Firmware, 315 5g Iot Modem and 321 more 2025-10-03 8.2 High
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2025-21438 1 Qualcomm 86 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 83 more 2025-10-03 7.8 High
Memory corruption while IOCTL call is invoked from user-space to read board data.
CVE-2025-10954 2 Phonenumbers Project, Textit 2 Phonenumbers, Phonenumbers 2025-10-03 5.3 Medium
Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range".
CVE-2014-2357 1 Subnet 1 Substation Server 2025-10-03 N/A
The GPT library in the Telegyr 8979 Master Protocol application in SUBNET SubSTATION Server 2 before SSNET 2.12 HF18808 allows remote attackers to cause a denial of service (persistent service crash) via a long RTU-to-Master message.