Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In June 2025
There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requirements, privileges, or user interaction required. Loss of availability is high; there is no impact on confidentiality or integrity.
CVSS Score
8.7
EPSS Score
0.004
Published
2025-06-12
An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.
CVSS Score
3.7
EPSS Score
0.003
Published
2025-06-12
Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and 5.7 before 05.71.01. The SMM module has an SMM call out vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.
CVSS Score
7.5
EPSS Score
0.002
Published
2025-06-12
Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially exploit this vulnerability, leading to Information disclosure.
CVSS Score
7.1
EPSS Score
0.001
Published
2025-06-12
Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated HTTP GET request to the /goform/openSchedWifi endpoint
CVSS Score
7.5
EPSS Score
0.006
Published
2025-06-12
go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
CVSS Score
6.5
EPSS Score
0.004
Published
2025-06-12
uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is fixed in v1.2.15.
CVSS Score
6.5
EPSS Score
0.004
Published
2025-06-12
pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.
CVSS Score
5.4
EPSS Score
0.002
Published
2025-06-12
The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.
CVSS Score
3.1
EPSS Score
0.004
Published
2025-06-12
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect traffic that is meant to be internal to their own hosted services and gathering information.
CVSS Score
8.8
EPSS Score
0.003
Published
2025-06-12


Contact Us

Shodan ® - All rights reserved