Post

2025-06-07 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2023-38674PaddlePaddle - PaddlePaddleFPE in paddle.nanmedian in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.CVSS3.1: 4.7 - MEDIUM0Exploitation: pocAutomatable: noTechnical Impact: partialFPE in paddle.nanmediangithub
CVE-2024-13087QNAP Systems Inc. - QuRouterA command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and laterCVSS4.0: 2.4 - LOW0Exploitation: noneAutomatable: noTechnical Impact: partialQHoragithub
CVE-2023-25995choicehomemortgage - AI Mortgage CalculatorImproper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) vulnerability in choicehomemortgage AI Mortgage Calculator allows PHP Local File Inclusion. This issue affects AI Mortgage Calculator: from n/a through 1.0.1.CVSS3.1: 7.5 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: totalWordPress AI Mortgage Calculator <= 1.0.1 - Local File Inclusion Vulnerabilitygithub
This post is licensed under CC BY 4.0 by the author.