Post

2025-07-30 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2024-42651n/a - n/aNanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.CNA n/a CVSS3.1: 7.5 - HIGH0 1 2Exploitation: pocAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2025-28170n/a - n/aGrandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.CNA n/a CVSS3.1: 7.6 - HIGH0 1Exploitation: pocAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2014-125114i-Ftp - i-FtpA stack-based buffer overflow vulnerability exists in i-Ftp version 2.20 due to improper handling of the Time attribute within Schedule.xml. By placing a specially crafted Schedule.xml file in the i-Ftp application directory, a remote attacker can trigger a buffer overflow during scheduled download parsing, potentially leading to arbitrary code execution or a crash.CVSS4.0: 8.4 - HIGH0 1 2 3Exploitation: pocAutomatable: noTechnical Impact: totali-Ftp 2.20 Schedule.xml Stack-Based Buffer Overflowgithub
This post is licensed under CC BY 4.0 by the author.