Post

2025-06-14 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2023-43535Qualcomm, Inc. - SnapdragonMemory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.CVSS3.1: 8.4 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: partialImproper Validation of Array Index in Displaygithub
CVE-2025-28382n/a - n/aAn issue in the openc3-api/tables endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.CNA n/a CVSS3.1: 7.5 - HIGH0 1Exploitation: pocAutomatable: yesTechnical Impact: partialundefinedgithub
CVE-2022-4976ETJ - Archive::Unzip::BurstArchive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilities. The bundled library is affected by CVE-2014-8139, CVE-2014-8140 and CVE-2014-8141.CNA n/a CVSS3.1: 9.8 - CRITICAL0Exploitation: noneAutomatable: yesTechnical Impact: totalArchive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilitiesgithub
CVE-2023-20599AMD - AMD EPYC™ 7002 Series ProcessorsAMD - AMD EPYC™ 7003 Series ProcessorsAMD - AMD Ryzen™ Threadripper™ 3000 ProcessorsAMD - AMD Ryzen™ Threadripper™ PRO 3000 WX ProcessorsAMD - AMD Ryzen™ Threadripper™ PRO 5000 WX ProcessorsAMD - AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ GraphicsAMD - AMD EPYC™ Embedded 7002 Series ProcessorsAMD - AMD EPYC™ Embedded 7003 Series ProcessorsImproper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86, resulting in potential loss of control of cryptographic key pointer/index, leading to loss of integrity or confidentiality.CVSS3.1: 7.9 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: totalundefinedgithub
CVE-2024-38823VMware - SALTSalt’s request server is vulnerable to replay attacks when not using a TLS encrypted transport.CVSS3.1: 2.7 - LOW0 1Exploitation: noneAutomatable: noTechnical Impact: partialCVE-2024-38823 Salt Advisorygithub
CVE-2025-29902Telex - Remote Dispatch Console ServerRTS - VLink Virtual Matrix SoftwareRemote code execution that allows unauthorized users to execute arbitrary code on the server machine.CVSS3.1: 10 - CRITICAL0Exploitation: noneAutomatable: yesTechnical Impact: totalundefinedgithub
This post is licensed under CC BY 4.0 by the author.