Medium · CVSS 6.3
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary executables. If modified to bypass protection mechanisms, this malicious code will be run when the card is inserted into an 8840 Clinician Programmer.
Published Jul 13, 2018 · Updated Aug 26, 2025
Medium · CVSS 4.6
Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card do not encrypt PII and PHI while at rest.
Published May 18, 2018 · Updated Jun 27, 2025
Medium · CVSS 5.4
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.
Published Aug 24, 2022 · Updated Jun 17, 2025
High · CVSS 8.8
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
Published Oct 26, 2018 · Updated Jun 9, 2025
High · CVSS 7.8
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
Published Feb 13, 2018 · Updated Jun 9, 2025
High · CVSS 7.4
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
Published Jan 11, 2019 · Updated Jun 9, 2025
High · CVSS 7.5
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.
Published Jan 11, 2019 · Updated Jun 9, 2025
High · CVSS 7
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
Published Oct 26, 2018 · Updated Jun 9, 2025
High · CVSS 7.8
A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.
Published Oct 26, 2018 · Updated Jun 9, 2025
High · CVSS 7.5
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
Published May 8, 2018 · Updated Jun 9, 2025
Medium · CVSS 4.3
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
Published Jan 11, 2019 · Updated Jun 9, 2025
High · CVSS 8
BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in after commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e.
Published Jun 26, 2018 · Updated Jun 9, 2025
Medium · CVSS 6.5
Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".
Published Jun 26, 2018 · Updated Jun 9, 2025
High · CVSS 7.5
An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification in udhcp_get_option() in networking/udhcp/common.c that 4-byte options are indeed 4 bytes.
Published Jan 9, 2019 · Updated Jun 9, 2025
Unknown · CVSS Not scored
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.
Published Jun 17, 2018 · Updated Jun 9, 2025
High · CVSS 7.5
An unauthenticated remote attacker may use an uncontrolled resource consumption in the IEC 61131 program of the affected products by creating large amounts of network traffic that needs to be handled by the ILC. This results in a Denial-of-Service of the device.
Published Jun 4, 2025 · Updated Jun 4, 2025
Critical · CVSS 9.8
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
Published Jan 8, 2024 · Updated Jun 3, 2025
Medium · CVSS 5.1
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.
Published May 31, 2025 · Updated Jun 2, 2025
High · CVSS 7.5
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
Published Jun 24, 2019 · Updated May 30, 2025
Unknown · CVSS Not scored
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device value.
Published Apr 25, 2018 · Updated May 30, 2025
Unknown · CVSS Not scored
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is XSS in invitation mail received from a different user, who can modify the HTML in that mail before sending it.
Published Apr 25, 2018 · Updated May 30, 2025
Unknown · CVSS Not scored
An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency credentials in cleartext in the logs (present in the DEBUG folder) that can be accessed by anyone. NOTE: The vendor disputes this as a vulnerability since the disclosure of a local account password (actually an alpha numeric passcode) is achievable only when a custom registry key is added to the windows registry. This action requires administrator access and the registry key is only provided by support staff at securenvoy to troubleshoot customer issues.
Published Mar 18, 2019 · Updated May 30, 2025
Unknown · CVSS Not scored
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a modified "vaultize_session_id" value in a cookie.
Published Apr 25, 2018 · Updated May 30, 2025
Unknown · CVSS Not scored
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature.
Published Apr 25, 2018 · Updated May 30, 2025
Unknown · CVSS Not scored
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS on the file or folder download pop-up via a crafted file or folder name.
Published Apr 25, 2018 · Updated May 30, 2025
Unknown · CVSS Not scored
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is anonymous reflected XSS on the error page via a /share/error?message= URI.
Published Apr 25, 2018 · Updated May 30, 2025
Unknown · CVSS Not scored
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on the FlexPaperViewer SWF reader, and export files that should have been restricted, via vectors involving page-by-page access to a document in SWF format.
Published Apr 25, 2018 · Updated May 30, 2025
Unknown · CVSS Not scored
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS via the optional message field of a file request.
Published Apr 25, 2018 · Updated May 30, 2025
High · CVSS 7.5
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.
Published Dec 12, 2023 · Updated May 27, 2025
Medium · CVSS 6.9
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
Published May 23, 2025 · Updated May 23, 2025
Medium · CVSS 6.2
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of the monitor's communication interfaces, including the interface between the monitor and implantable cardiac device. An attacker with physical access to the device can exploit other vulnerabilities to access this debug functionality. This debug functionality provides the ability to read and write arbitrary memory values to implantable cardiac devices via inductive or short range wireless protocols. An attacker with close physical proximity to a target implantable cardiac device can use this debug functionality.
Published Jul 2, 2018 · Updated May 22, 2025
Medium · CVSS 6.4
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the password to gain privileged access to the operating system.
Published Jul 2, 2018 · Updated May 22, 2025
Medium · CVSS 4.8
Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could allow an attacker to read files on the system.
Published May 4, 2018 · Updated May 22, 2025
Medium · CVSS 4.9
Medtronic 2090 CareLink Programmer
uses a per-product username and password that is stored in a recoverable format.
Published May 4, 2018 · Updated May 22, 2025
High · CVSS 7.1
Medtronic 2090 CareLink Programmer
uses a virtual private network connection to securely download updates. It does not verify it is still connected to this virtual private network before downloading updates. The affected products initially establish an encapsulated IP-based VPN connection to a Medtronic-hosted update network. Once the VPN is established, it makes a request to a HTTP (non-TLS) server across the VPN for updates, which responds and provides any available updates. The programmer-side (client) service responsible for this HTTP request does not check to ensure it is still connected to the VPN before making the HTTP request. Thus, an attacker could cause the VPN connection to terminate (through various methods and attack points) and intercept the HTTP request, responding with malicious updates via a man-in-the-middle attack. The affected products do not verify the origin or integrity of these updates, as it insufficiently relied on the security of the VPN. An attacker with remote network access to the programmer could influence these communications.
Published Jul 2, 2018 · Updated May 22, 2025
Medium · CVSS 4.6
Medtronic CareLink and Encore Programmers
do not encrypt or do not sufficiently encrypt sensitive
PII and PHI information while at rest .
Published Dec 14, 2018 · Updated May 22, 2025
Medium · CVSS 5.3
Medtronic MiniMed MMT
devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.
Published Aug 13, 2018 · Updated May 22, 2025
Medium · CVSS 4.8
Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as device serial numbers.
Published Aug 13, 2018 · Updated May 22, 2025
Critical · CVSS 9.8
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
Published Oct 12, 2022 · Updated May 16, 2025
Critical · CVSS 9.8
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
Published Oct 12, 2022 · Updated May 16, 2025
Medium · CVSS 6.1
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field.
Published Dec 31, 2018 · Updated May 6, 2025
Medium · CVSS 5.4
HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.
Published Dec 31, 2018 · Updated May 6, 2025
Medium · CVSS 5.4
CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.
Published Dec 31, 2018 · Updated May 6, 2025
High · CVSS 7.5
A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests.
Published Dec 31, 2018 · Updated May 6, 2025
Medium · CVSS 5.9
A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate resources. This affects all supported versions of HHVM (3.24.3 and 3.21.7 and below) when using the proxygen server to handle HTTP2 requests.
Published Dec 3, 2018 · Updated May 6, 2025
High · CVSS 7.8
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute. This issue affects osquery prior to v3.2.7
Published Dec 31, 2018 · Updated May 6, 2025
High · CVSS 8.1
The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
Published Dec 31, 2018 · Updated May 6, 2025
Medium · CVSS 5.4
Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter.
Published Dec 31, 2018 · Updated May 6, 2025
High · CVSS 8.1
The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.
Published Dec 31, 2018 · Updated May 6, 2025
High · CVSS 8.1
The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow.
Published Dec 31, 2018 · Updated May 6, 2025