Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-22403

CVE-2025-22403_CVE-2025-22403

In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to re...

Google Android 15 CVE
CRITICAL 9.8 CVE-2025-0075

CVE-2025-0075_CVE-2025-0075

In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to ...

Google Android 15 CVE
CRITICAL 9.8 CVE-2025-0074

CVE-2025-0074_CVE-2025-0074

In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remo...

Google Android 15 CVE
CRITICAL 9.6 CVE-2025-43728

CVE-2025-43728_CVE-2025-43728

Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote acces...

Dell ThinOS 10 N/A CVE
CRITICAL 9.4 CVE-2025-2313

RCE via Print.pl in uhcPrintServerPrint_CVE-2025-2313

In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter.

CGM CGM CLININET CVE
CRITICAL 9 CVE-2025-30039

Missing authentication in API returning a list of all active sessions_CVE-2025-30039

Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, inc...

CGM CGM CLININET CVE
CRITICAL 9 CVE-2025-30040

Missing authentication in API returning request logs containing session IDs_CVE-2025-30040

The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "/cgi-bin/CliniNET.prd/utils...

CGM CGM CLININET CVE
CRITICAL 9 CVE-2025-30041

Missing authentication in APIs returning statistical data along with session IDs_CVE-2025-30041

The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl"...

CGM CGM CLININET CVE
CRITICAL 9 CVE-2025-30055

Conditional RCE via the “system” function_CVE-2025-30055

The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code ...

CGM CGM CLININET CVE
CRITICAL 9.4 CVE-2025-30056

Calling system commands via RunCommand_CVE-2025-30056

The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code o...

CGM CGM CLININET CVE