VulDB Updates Updates
- CVE-2024-6538 | Red Hat OpenShift Container Platform 4 internet server-side request forgery (EUVD-2024-3382)by vuldb.com on November 7, 2025 at 3:56 am
A vulnerability labeled as critical has been found in Red Hat OpenShift Container Platform 4. This affects an unknown part of the file /api/dev-console/proxy/internet. The manipulation results in server-side request forgery. This vulnerability is reported as CVE-2024-6538. The attack can be launched remotely. No exploit exists.
- CVE-2024-54448 | LogicalDOC Community/Enterprise up to 9.0 Automation Scripting code injectionby vuldb.com on November 7, 2025 at 3:56 am
A vulnerability, which was classified as critical, has been found in LogicalDOC Community and Enterprise up to 9.0. Impacted is an unknown function of the component Automation Scripting. This manipulation causes code injection. This vulnerability is registered as CVE-2024-54448. Remote exploitation of the attack is possible. No exploit is available. It is advisable to upgrade the affected component.
- CVE-2024-54449 | LogicalDOC Community/Enterprise up to 9.0 API path traversalby vuldb.com on November 7, 2025 at 3:56 am
A vulnerability classified as critical has been found in LogicalDOC Community and Enterprise up to 9.0. This vulnerability affects unknown code of the component API. The manipulation leads to relative path traversal. This vulnerability is listed as CVE-2024-54449. The attack may be initiated remotely. There is no available exploit. It is recommended to upgrade the affected component.
- CVE-2025-23154 | Linux Kernel up to 6.12.23/6.13.11/6.14.2 io_req_post_cqe state issue (EUVD-2025-13089 / Nessus ID 240657)by vuldb.com on November 7, 2025 at 3:56 am
A vulnerability was found in Linux Kernel up to 6.12.23/6.13.11/6.14.2. It has been rated as problematic. Affected by this vulnerability is the function io_req_post_cqe. The manipulation leads to state issue. This vulnerability is referenced as CVE-2025-23154. The attack needs to be initiated within the local network. No exploit is available. Upgrading the affected component is advised.
- CVE-2024-12020 | LogicalDOC Enterprise JSP File cross site scriptingby vuldb.com on November 7, 2025 at 3:56 am
A vulnerability has been found in LogicalDOC Enterprise and classified as problematic. Affected is an unknown function of the component JSP File Handler. The manipulation leads to cross site scripting. This vulnerability is documented as CVE-2024-12020. The attack can be initiated remotely. There is not any exploit available.
- CVE-2025-23158 | Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2 empty_space out-of-bounds write (Nessus ID 237255 / WID-SEC-2025-0922)by vuldb.com on November 7, 2025 at 3:56 am
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2. Affected by this vulnerability is the function empty_space. Such manipulation leads to out-of-bounds write. This vulnerability is listed as CVE-2025-23158. The attack must be carried out from within the local network. There is no available exploit. Upgrading the affected component is recommended.
- CVE-2025-23151 | Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2 mhi_unprepare_from_transfer memory corruption (Nessus ID 237504 / WID-SEC-2025-0922)by vuldb.com on November 7, 2025 at 3:56 am
A vulnerability marked as critical has been reported in Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2. Affected is the function mhi_unprepare_from_transfer. This manipulation causes memory corruption. This vulnerability is tracked as CVE-2025-23151. The attack is only possible within the local network. No exploit exists. It is suggested to upgrade the affected component.
- CVE-2025-23152 | Linux Kernel up to 6.14.2 crc_t10dif_arch privilege escalation (Nessus ID 240657)by vuldb.com on November 7, 2025 at 3:56 am
A vulnerability classified as problematic has been found in Linux Kernel up to 6.14.2. Affected by this issue is the function crc_t10dif_arch. Performing manipulation results in privilege escalation. This vulnerability is cataloged as CVE-2025-23152. The attack must originate from the local network. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2025-23153 | Linux Kernel up to 6.14.2 crc_t10dif_arch privilege escalation (EUVD-2025-13083 / Nessus ID 240657)by vuldb.com on November 7, 2025 at 3:56 am
A vulnerability classified as problematic was found in Linux Kernel up to 6.14.2. This affects the function crc_t10dif_arch. Executing manipulation can lead to privilege escalation. This vulnerability is registered as CVE-2025-23153. The attack requires access to the local network. No exploit is available. Upgrading the affected component is advised.
- CVE-2025-23156 | Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2 media out-of-bounds (Nessus ID 237255 / WID-SEC-2025-0922)by vuldb.com on November 7, 2025 at 3:56 am
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2. This vulnerability affects unknown code of the component media. The manipulation leads to out-of-bounds read. This vulnerability is documented as CVE-2025-23156. The attack requires being on the local network. There is not any exploit available. It is advisable to upgrade the affected component.
- CVE-2024-29034 | CarrierWave up to 2.2.5/3.0.6 Incomplete Fix CVE-2023-49090 Content-Type interpretation conflictby vuldb.com on November 7, 2025 at 3:56 am
A vulnerability identified as problematic has been detected in CarrierWave up to 2.2.5/3.0.6. The affected element is an unknown function of the component Incomplete Fix CVE-2023-49090. This manipulation of the argument Content-Type causes interpretation conflict. This vulnerability is handled as CVE-2024-29034. The attack can be initiated remotely. There is not any exploit available. You should upgrade the affected component.
- CVE-2025-23157 | Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2 media out-of-bounds (Nessus ID 237255 / WID-SEC-2025-0922)by vuldb.com on November 7, 2025 at 3:56 am
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2. This issue affects some unknown processing of the component media. The manipulation results in out-of-bounds read. This vulnerability is reported as CVE-2025-23157. The attacker must have access to the local network to execute the attack. No exploit exists. You should upgrade the affected component.
- CVE-2025-23155 | Linux Kernel up to 6.13.11/6.14.2 irq_desc Local Privilege Escalation (EUVD-2025-13082 / Nessus ID 240657)by vuldb.com on November 7, 2025 at 3:56 am
A vulnerability has been found in Linux Kernel up to 6.13.11/6.14.2 and classified as problematic. This affects the function irq_desc. Performing manipulation results in Local Privilege Escalation. This vulnerability is reported as CVE-2025-23155. The attack requires a local approach. No exploit exists. The affected component should be upgraded.
- CVE-2007-2249 | Phorum 5.1.20 users.php POST privilege escalation (EDB-29889 / BID-23616)by vuldb.com on November 7, 2025 at 3:47 am
A vulnerability classified as critical has been found in Phorum 5.1.20. This affects an unknown function of the file include/controlcenter/users.php. This manipulation of the argument POST causes privilege escalation. This vulnerability is registered as CVE-2007-2249. Remote exploitation of the attack is possible. Furthermore, an exploit is available. It is recommended to upgrade the affected component.
- CVE-2007-2249 | Phorum admin.php smiley_id cross site scripting (EDB-29889 / BID-23616)by vuldb.com on November 7, 2025 at 3:47 am
A vulnerability labeled as problematic has been found in Phorum. Affected is an unknown function of the file admin.php. Executing manipulation of the argument smiley_id can lead to basic cross site scripting. This vulnerability is registered as CVE-2007-2249. It is possible to launch the attack remotely. Furthermore, an exploit is available.
- CVE-2007-2249 | Phorum admin.php sql injection (EDB-29889 / BID-23616)by vuldb.com on November 7, 2025 at 3:47 am
A vulnerability marked as critical has been reported in Phorum. Affected by this vulnerability is an unknown functionality of the file admin.php. The manipulation leads to sql injection. This vulnerability is documented as CVE-2007-2249. The attack can be initiated remotely. Additionally, an exploit exists.
- CVE-2007-1140 | Barekoncept pheap edit.php filename path traversal (EDB-29635 / BID-22670)by vuldb.com on November 7, 2025 at 3:47 am
A vulnerability classified as problematic has been found in Barekoncept pheap. Impacted is an unknown function of the file edit.php. This manipulation of the argument filename causes path traversal. This vulnerability appears as CVE-2007-1140. The attack may be initiated remotely. In addition, an exploit is available.
- CVE-2007-2338 | Phorum 5.1.20 banlist.php delete cross-site request forgery (EDB-29891 / XFDB-34078)by vuldb.com on November 7, 2025 at 3:47 am
A vulnerability described as problematic has been identified in Phorum 5.1.20. This vulnerability affects unknown code of the file include/admin/banlist.php. The manipulation of the argument delete results in cross-site request forgery. This vulnerability was named CVE-2007-2338. The attack may be performed from remote. In addition, an exploit is available. Upgrading the affected component is recommended.
- CVE-2007-6670 | Phpcredo PHCDownload 1.1 search.php string sql injection (EDB-30957 / BID-27066)by vuldb.com on November 7, 2025 at 3:47 am
A vulnerability was found in Phpcredo PHCDownload 1.1. It has been declared as critical. Affected by this issue is some unknown functionality of the file search.php. Such manipulation of the argument string leads to sql injection. This vulnerability is uniquely identified as CVE-2007-6670. The attack can be launched remotely. Moreover, an exploit is present.
- CVE-2007-6669 | Phpcredo PHCDownload 1.1 search.php string cross site scripting (EDB-30958 / XFDB-39420)by vuldb.com on November 7, 2025 at 3:47 am
A vulnerability was found in Phpcredo PHCDownload 1.1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the file search.php. This manipulation of the argument string causes cross site scripting. This vulnerability is handled as CVE-2007-6669. The attack can be initiated remotely. Additionally, an exploit exists.
- CVE-2023-40809 | OpenCRX 5.2.0 Activity Search Criteria-Activity Number cross site scripting (EUVD-2023-2999)by vuldb.com on November 7, 2025 at 3:39 am
A vulnerability was found in OpenCRX 5.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Activity Search Criteria-Activity Number. Such manipulation leads to basic cross site scripting. This vulnerability is uniquely identified as CVE-2023-40809. The attack can be launched remotely. Moreover, an exploit is present.
- CVE-2023-26101 | Progress Flowmon FPI up to 12.0.x path traversal (EUVD-2023-29974)by vuldb.com on November 7, 2025 at 3:39 am
A vulnerability described as critical has been identified in Progress Flowmon FPI up to 12.0.x. This impacts an unknown function. Such manipulation leads to path traversal. This vulnerability is traded as CVE-2023-26101. Access to the local network is required for this attack to succeed. There is no exploit available. Upgrading the affected component is recommended.
- CVE-2023-48648 | Concrete CMS up to 8.5.12/9.2.1 File Creation Mkdir permission (EUVD-2023-2998)by vuldb.com on November 7, 2025 at 3:39 am
A vulnerability described as critical has been identified in Concrete CMS up to 8.5.12/9.2.1. Impacted is the function Mkdir of the component File Creation Handler. The manipulation results in permission issues. This vulnerability is reported as CVE-2023-48648. The attacker must have access to the local network to execute the attack. No exploit exists. Upgrading the affected component is recommended.
- CVE-2010-1071 | phpMDJ 1.0.3 profil.php ID sql injection (EDB-11083 / XFDB-55516)by vuldb.com on November 7, 2025 at 3:33 am
A vulnerability identified as critical has been detected in phpMDJ 1.0.3. This affects an unknown function of the file profil.php. The manipulation of the argument ID leads to sql injection. This vulnerability is listed as CVE-2010-1071. The attack may be initiated remotely. In addition, an exploit is available.
- CVE-2010-3029 | PHPKick 0.8 statistics.php gameday sql injection (EDB-14578 / OSVDB-67200)by vuldb.com on November 7, 2025 at 3:33 am
A vulnerability was found in PHPKick 0.8. It has been rated as critical. The impacted element is an unknown function of the file statistics.php. Performing manipulation of the argument gameday results in sql injection. This vulnerability is cataloged as CVE-2010-3029. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
- CVE-2010-0974 | PHPCityPortal Spotlight video_show.php ID sql injection (EDB-11678 / XFDB-56811)by vuldb.com on November 7, 2025 at 3:33 am
A vulnerability classified as critical was found in PHPCityPortal. Affected by this vulnerability is an unknown functionality of the file video_show.php of the component Spotlight. The manipulation of the argument ID results in sql injection. This vulnerability is identified as CVE-2010-0974. The attack can be executed remotely. Additionally, an exploit exists.
- CVE-2010-0975 | PHPCityPortal external.php url code injection (EDB-11678 / XFDB-56812)by vuldb.com on November 7, 2025 at 3:33 am
A vulnerability, which was classified as critical, has been found in PHPCityPortal. Affected by this issue is some unknown functionality of the file external.php. This manipulation of the argument url causes code injection. This vulnerability is tracked as CVE-2010-0975. The attack is possible to be carried out remotely. Moreover, an exploit is present.
- CVE-2010-1361 | Glarotech PHPepperShop 2.5 darstellen cross site scripting (EDB-33487 / XFDB-55561)by vuldb.com on November 7, 2025 at 3:33 am
A vulnerability, which was classified as problematic, has been found in Glarotech PHPepperShop 2.5. The impacted element is an unknown function. The manipulation of the argument darstellen leads to cross site scripting. This vulnerability is uniquely identified as CVE-2010-1361. The attack is possible to be carried out remotely. Moreover, an exploit is present.
- CVE-2010-0953 | phpCOIN 1.2.1 mod.php mod path traversal (EDB-11641 / XFDB-56721)by vuldb.com on November 7, 2025 at 3:33 am
A vulnerability labeled as problematic has been found in phpCOIN 1.2.1. Affected by this vulnerability is an unknown functionality of the file mod.php. Such manipulation of the argument mod leads to path traversal. This vulnerability is listed as CVE-2010-0953. The attack may be performed from remote. In addition, an exploit is available.
- CVE-2010-4143 | phpCheckZ 1.1.0 chart.php ID sql injection (EDB-15284 / OSVDB-68740)by vuldb.com on November 7, 2025 at 3:33 am
A vulnerability marked as critical has been reported in phpCheckZ 1.1.0. Affected by this vulnerability is an unknown functionality of the file chart.php. This manipulation of the argument ID causes sql injection. This vulnerability is tracked as CVE-2010-4143. The attack is possible to be carried out remotely. Moreover, an exploit is present.





