Vulnerabilities (CVE)

Filtered by CWE-941
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-53899 1 Accellion 1 Kiteworks Managed File Transfer 2025-12-03 N/A 7.2 HIGH
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges on the system under certain circumstances to intercept upstream communication which could lead to an escalation of privileges. This issue has been patched in version 9.1.0.
CVE-2025-0036 2025-06-12 N/A 3.2 LOW
In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to and read from invalid locations as well as returning incorrect cryptographic data.
CVE-2024-34947 2025-03-25 N/A 9.4 CRITICAL
Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack.
CVE-2024-29415 2025-01-17 N/A 8.1 HIGH
The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.
CVE-2022-4847 1 Usememos 1 Memos 2024-11-21 N/A 6.5 MEDIUM
Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.