search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2025-05-09 2025-05-09 2025-05-09 VU#760160 libexpat library is vulnerable to DoS attacks through stack overflow
2025-05-07 2025-05-07 2025-05-07 VU#722229 Radware Cloud Web Application Firewall Vulnerable to Filter Bypass
2025-05-02 2025-05-02 2025-05-02 VU#360686 Digigram PYKO-OUT audio-over-IP (AoIP) does not require a password by default
2025-04-25 2025-04-25 2025-04-29 VU#667211 Various GPT services are vulnerable to two systemic jailbreaks, allows for bypass of safety guardrails
2024-04-09 2024-04-09 2025-04-22 VU#155143 Linux kernel on Intel systems is susceptible to Spectre v2 attacks
2025-02-28 2025-03-01 2025-04-14 VU#726882 Paragon Software Hard Disk Manager product line contains five memory vulnerabilities within its BioNTdrv.sys driver that allow for privilege escalation and denial-of-service (DoS) attacks
2025-01-14 2025-01-14 2025-04-09 VU#952657 Rsync contains six vulnerabilities
2025-04-03 2025-04-03 2025-04-03 VU#252619 Multiple deserialization vulnerabilities in PyTorch Lightning 2.4.0 and earlier versions
2012-06-27 2012-06-27 2025-03-20 VU#971035 0.5 Simple Certificate Enrollment Protocol (SCEP) does not strongly authenticate certificate requests
2025-01-17 2025-01-17 2025-02-24 VU#199397 Insecure Implementation of Tunneling Protocols (GRE/IPIP/4in6/6in4)
2025-02-11 2025-02-11 2025-02-11 VU#148244 PandasAI interactive prompt function can be exploited to run arbitrary Python code through prompt injection, which can lead to remote code execution (RCE)
2022-01-31 2022-01-31 2025-02-03 VU#119678 Samba vfs_fruit module insecurely handles extended file attributes
2025-01-30 2025-01-30 2025-01-30 VU#733789 ChatGPT-4o contains security bypass vulnerability through time and search functions called "Time Bandit"
2023-02-28 2023-02-28 2025-01-30 VU#782720 TCG TPM2.0 implementations vulnerable to memory corruption
2025-01-14 2025-01-14 2025-01-21 VU#529659 Howyar Reloader UEFI bootloader vulnerable to unsigned software execution

Sponsored by CISA.